legal-work-plugin

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and suggests installation from a repository belonging to the Anthropic organization.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it processes untrusted external data (contracts and NDAs) and possesses the capability to write to tools like Slack and Jira.
  • Ingestion points: Document content is ingested via user-provided text or files from services like Box, Egnyte, and Microsoft 365 as described in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters defined to isolate the processed contract text from the agent's instructions.
  • Capability inventory: The skill can interact with Slack, Box, Egnyte, Jira, and Microsoft 365.
  • Sanitization: No sanitization or validation of the ingested document content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 07:53 PM
Security Audit — agent-trust-hub — legal-work-plugin