investigation-open

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface area. It ingests untrusted user input (legal allegations) and incorporates it into generated investigation logs and evidence lists. \n
  • Ingestion points: The argument-hint and the user-provided complaint description in SKILL.md. \n
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the logic. \n
  • Capability inventory: The skill is instructed to perform file system operations, specifically creating and updating investigation logs. \n
  • Sanitization: The skill lacks explicit sanitization or validation of the external content before processing. \n- [COMMAND_EXECUTION]: The skill performs targeted read access to the local filesystem at ~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md. While used for legitimate context loading within the vendor's toolset, this represents access to the agent's hidden configuration directory.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:07 AM
Security Audit — agent-trust-hub — investigation-open