worker-classification

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: Analyzed the skill's file system access patterns. It reads configuration files located at ~/.claude/plugins/config/claude-for-legal/employment-legal/CLAUDE.md and case-specific matter.md files to maintain jurisdictional context and case history. This behavior is restricted to the specific configuration directory of the legal suite and is essential for its intended functionality.
  • [EXTERNAL_DOWNLOADS]: Evaluated the integration with external legal research tools (referenced as yuandian MCP) and network search capabilities. These tools are used to retrieve current regulations and judicial standards. The skill includes a verification step where the agent must inform the user if sources have lower confidence levels, requiring explicit approval before proceeding.
  • [PROMPT_INJECTION]: Assessed the skill for indirect prompt injection surfaces and internal control logic. It ingests data from case files (matter.md) and user input describing work arrangements. The skill mitigates risks by using structured analysis tables as boundary markers. Additionally, it contains defensive instructions (the "hard threshold" logic) to prevent the agent from providing unauthorized advice on existing relationships, enforcing a scope boundary between planning and remediation.
  • [COMMAND_EXECUTION]: The skill invokes other modular components within the same legal toolset (e.g., /employment-legal:matter-workspace and /employment-legal:hiring-review). These internal calls are used for project management and transitioning to different stages of the legal workflow rather than executing arbitrary system commands.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 07:07 AM
Security Audit — agent-trust-hub — worker-classification