internal-investigation
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a localized workflow for managing sensitive legal information without the use of external network calls, remote code downloads, or system-level command execution.
- [PROMPT_INJECTION]: The skill is designed to process external documents and interview notes (Mode 2: Add data), which introduces an indirect prompt injection surface where adversarial content in documents could attempt to influence the agent's summary or conclusions. However, because the skill has no network access and operates via highly structured templates, this risk is minimal and consistent with its primary purpose.
- Ingestion points: 'Mode 2: Add data' in SKILL.md (processing user-provided documents and notes).
- Boundary markers: Absent.
- Capability inventory: Reading and writing files within the designated local matter directory (SKILL.md).
- Sanitization: Absent.
Audit Metadata