related-skills-surfacer

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill reads configuration data from ~/.claude/plugins/config/claude-for-legal/legal-builder-hub/CLAUDE.md to determine user preferences and installed skills. It also maintains a history of recommended items in references/surfaced.json. These operations are standard for personalized recommendation logic and are scoped to the vendor's local configuration directory.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests recent task descriptions as untrusted data to perform keyword matching against a registry. While this represents a potential surface for indirect prompt injection, the risk is mitigated as the skill only outputs predefined recommendations from a registry and does not execute the matching data as commands.
  • [COMMAND_EXECUTION]: The skill references a command /legal-builder-hub:skill-installer [名称] to be suggested to the user. This command is presented as a text recommendation for the user to initiate manually, rather than being executed automatically by the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 01:02 AM
Security Audit — agent-trust-hub — related-skills-surfacer