launch-review

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, such as Product Requirement Documents (PRDs), Lark (Feishu) links, and comments from project management tools (Jira, DingTalk, Teambition). This creates a surface for indirect prompt injection where instructions hidden within these documents could attempt to manipulate the legal review findings or bypass risk calibrations.
  • Ingestion points: SKILL.md (Step 1, Step 2) and references/seven-category-framework.md.
  • Boundary markers: Absent. The skill lacks instructions for the agent to ignore or delimit instructions contained within the analyzed PRDs or ticket comments.
  • Capability inventory: Uses Model Context Protocol (MCP) tools for document retrieval and for posting comments back to project trackers.
  • Sanitization: The skill includes a 'Safety Release' and 'Destination Check' mechanism to sanitize outputs before sharing, but it does not include sanitization or verification steps for the untrusted inputs being analyzed.
  • [NO_CODE]: The skill consists entirely of markdown instructions and reference frameworks. No executable scripts, binaries, or complex automation files are included in the distribution.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — launch-review