semester-handoff

Pass

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests and processes untrusted data from client communication logs and intake summaries, which serves as a vector for indirect prompt injection attacks designed to manipulate the agent's summary output. \n- Ingestion points: Untrusted content is read from ~/.claude/plugins/config/claude-for-legal/legal-clinic/client-comms/[案件编号]/log.md and general case intake summaries. \n- Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat embedded content as untrusted or to ignore potentially malicious instructions within the logs. \n- Capability inventory: The skill possesses the capability to write summarized reports to the local file system in the ~/.claude/plugins/config/claude-for-legal/legal-clinic/handoffs/ directory. \n- Sanitization: No input validation or sanitization mechanisms are described for the historical communication logs before they are incorporated into the prompt context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 12, 2026, 01:02 AM
Security Audit — agent-trust-hub — semester-handoff