saas-msa-review
Pass
Audited by Gen Agent Trust Hub on May 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is composed entirely of instructional markdown without any accompanying scripts, executables, or tool invocations. It operates solely within the language model's reasoning capabilities to analyze text provided in the user's workspace.
- [SAFE]: The instructions include specific safety guardrails for the agent, such as '不得无声补全' (no silent completion/no hallucinations) and mandatory source attribution requirements, which mitigate the risk of generating inaccurate legal advice.
- [SAFE]: No network operations, credential access, or persistence mechanisms are present. The skill references local context files like
CLAUDE.mdandmatter.mdto maintain consistency with the user's defined workspace. - [PROMPT_INJECTION]: The skill is a document processing surface that ingests untrusted third-party data (SaaS agreements). While it lacks boundary markers or sanitization logic to separate user text from instructions, the impact is minimal as the skill does not possess sensitive capabilities like network access or shell execution that could be exploited via indirect injection.
Audit Metadata