2026-legal-research-agent

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to scrape content from external websites (government portals, legislature databases, and legal aid sites) and extract legal metadata. This ingestion of untrusted external content into the agent's context creates an attack surface where malicious instructions hidden on a compromised or attacker-controlled legal site could influence the agent's behavior.
  • Ingestion points: Untrusted data is ingested via Firecrawl into JSON files located in src/data/scraped/states/, as described in SKILL.md and processed by the scripts/validate-scraped-data.ts script.
  • Boundary markers: While SKILL.md includes a "Data Validation Checklist" to ensure technical accuracy (citations, URLs, dates), it lacks explicit prompt boundary markers or "ignore instructions" directives to prevent the agent from obeying instructions found within the scraped fullText of statutes or court pages.
  • Capability inventory: The skill possesses the capability to execute local TypeScript scripts via tsx (e.g., scripts/firecrawl/run-p0.ts and scripts/validate-scraped-data.ts) and perform file system operations (read/write) within the project directory.
  • Sanitization: The instructions recommend a "Manual review + cleanup" step before integrating scraped data into the final state data files, which provides a human-in-the-loop security check, but there is no automated sanitization for the large-scale content processing phase.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 12:13 AM
Security Audit — agent-trust-hub — 2026-legal-research-agent