2026-legal-research-agent
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to scrape content from external websites (government portals, legislature databases, and legal aid sites) and extract legal metadata. This ingestion of untrusted external content into the agent's context creates an attack surface where malicious instructions hidden on a compromised or attacker-controlled legal site could influence the agent's behavior.
- Ingestion points: Untrusted data is ingested via Firecrawl into JSON files located in
src/data/scraped/states/, as described inSKILL.mdand processed by thescripts/validate-scraped-data.tsscript. - Boundary markers: While
SKILL.mdincludes a "Data Validation Checklist" to ensure technical accuracy (citations, URLs, dates), it lacks explicit prompt boundary markers or "ignore instructions" directives to prevent the agent from obeying instructions found within the scrapedfullTextof statutes or court pages. - Capability inventory: The skill possesses the capability to execute local TypeScript scripts via
tsx(e.g.,scripts/firecrawl/run-p0.tsandscripts/validate-scraped-data.ts) and perform file system operations (read/write) within the project directory. - Sanitization: The instructions recommend a "Manual review + cleanup" step before integrating scraped data into the final state data files, which provides a human-in-the-loop security check, but there is no automated sanitization for the large-scale content processing phase.
Audit Metadata