material-contract-schedule

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows standard operational patterns for a business-focused AI agent extension, focusing on structured data extraction and formatting for legal professionals.
  • [PROMPT_INJECTION]: Analysis of the indirect prompt injection surface identifies the ingestion of untrusted external content as part of its primary function.
  • Ingestion points: Material contract definitions from SPA drafts and findings from 'diligence-issue-extraction' (SKILL.md).
  • Boundary markers: Absent; the skill does not define specific delimiters or instructions to ignore embedded commands in the ingested legal documents.
  • Capability inventory: The skill performs file-read and file-write operations within the designated matter workspace in ~/.claude/plugins/config/claude-for-legal/.
  • Sanitization: No sanitization or content validation is performed prior to the interpolation of external text into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — material-contract-schedule