my-eo-contract-drafter
Pass
Audited by Gen Agent Trust Hub on Aug 11, 2026
Risk Level: SAFECREDENTIALS_UNSAFEDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The file 'lib/parties.py' contains hardcoded corporate financial information, specifically the bank account details for '주식회사 이오스튜디오' (Woori Bank 1005-403-956285).
- [DATA_EXFILTRATION]: The registry 'lib/parties.py' contains Personal Identifiable Information (PII) including a private cell phone number (010-6755-7980) and emails for third-party business representatives.
- [DATA_EXFILTRATION]: The skill implements file system write operations via the 'python-docx' library in the 'templates/' directory. The 'output_path' parameter is determined by user-supplied values or agent logic, creating a risk of arbitrary file writing if not strictly restricted by the environment.
- [PROMPT_INJECTION]: Instructions in 'SKILL.md' mandate a '7-stage playbook' and the use of a 'Lisa legal lens' to override the agent's default decision-making process, which can be used to bypass standard safety or procedural constraints.
Audit Metadata