contracts

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill focuses on instructional guidance for contract drafting, emphasizing clear legal boundaries. It explicitly instructs the agent to state it is not a lawyer and to require a licensed attorney's review before any document is signed, which aligns with legal and ethical guidelines.
  • [COMMAND_EXECUTION]: A shell script (scripts/verify.sh) is provided to automate checks for plain-language rules and risk-carve-out compliance. The script uses standard Unix utilities like grep and sed to identify archaic legalese or missing liability carve-outs. It implements safety checks, such as verifying file existence and quoting arguments to prevent command injection.
  • [SAFE]: The skill promotes data security by advising the operator to obtain informed consent and exercise caution before pasting confidential counterparty information into untrusted or self-learning AI models.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to review and interpret untrusted external data, such as contract drafts from counterparties. This risk is categorized as low given the skill's reliance on human/attorney review for final verification.
  • Ingestion points: The skill ingests and reviews counterparty drafts (e.g., MSAs, SOWs) provided by the user (SKILL.md, evals/cases.yaml).
  • Boundary markers: The instructions do not specify technical delimiters or strict sanitization routines for input contract text, though they provide conceptual guidance on risk identification.
  • Capability inventory: The skill's primary capability is text generation and analysis. No tools for file system modification, network communication, or arbitrary command execution are utilized by the agent during runtime.
  • Sanitization: No automated escaping or validation of external text is performed by the skill's internal logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — contracts