vendor-agreement-review

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill reads legal review guidelines from a configuration file located at ~/.claude/plugins/config/claude-for-legal/commercial-legal/CLAUDE.md. While this path is outside the immediate project workspace, it appears to be the intended storage location for the plugin's persistent internal standards. This is a legitimate functional requirement for maintaining consistent legal review criteria across different sessions.
  • [COMMAND_EXECUTION]: The skill references potential integration with external Model Context Protocol (MCP) tools for contract management systems and electronic signature platforms (e.g., e签宝, 法大大). The instructions explicitly state that no signatures should be sent without direct user authorization, providing a behavioral safeguard against unauthorized actions via these tools.
  • [PROMPT_INJECTION]: As the skill's primary function is to process untrusted external text (vendor agreements), it is inherently susceptible to indirect prompt injection (Category 8). An attacker could theoretically embed instructions within a contract designed to manipulate the AI's review. However, the skill incorporates mitigation strategies by instructing the AI to provide exact quotes from the contract and cross-reference them against internal guidelines, rather than relying solely on summarized intent.
  • [SAFE]: The skill implements professional best practices, such as verifying user roles (legal vs. non-legal), checking for confidentiality privilege (attorney-client privilege), and providing jurisdiction-specific warnings (citing Chinese Civil Code). It does not contain any obfuscated code, unauthorized network calls, or persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:06 AM
Security Audit — agent-trust-hub — vendor-agreement-review