investigation-open
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface area. It ingests untrusted user input (legal allegations) and incorporates it into generated investigation logs and evidence lists. \n
- Ingestion points: The
argument-hintand the user-provided complaint description inSKILL.md. \n - Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the logic. \n
- Capability inventory: The skill is instructed to perform file system operations, specifically creating and updating investigation logs. \n
- Sanitization: The skill lacks explicit sanitization or validation of the external content before processing. \n- [COMMAND_EXECUTION]: The skill performs targeted read access to the local filesystem at
~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md. While used for legitimate context loading within the vendor's toolset, this represents access to the agent's hidden configuration directory.
Audit Metadata