semester-handoff
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests and processes untrusted data from client communication logs and intake summaries, which serves as a vector for indirect prompt injection attacks designed to manipulate the agent's summary output. \n- Ingestion points: Untrusted content is read from
~/.claude/plugins/config/claude-for-legal/legal-clinic/client-comms/[案件编号]/log.mdand general case intake summaries. \n- Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat embedded content as untrusted or to ignore potentially malicious instructions within the logs. \n- Capability inventory: The skill possesses the capability to write summarized reports to the local file system in the~/.claude/plugins/config/claude-for-legal/legal-clinic/handoffs/directory. \n- Sanitization: No input validation or sanitization mechanisms are described for the historical communication logs before they are incorporated into the prompt context.
Audit Metadata