legal-finance

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements standardized protocols for operational traceability and security hygiene. It restricts agent activities to a defined tool allowlist and explicitly mandates the redaction of sensitive data (PII/secrets) when processing external inputs.- [SAFE]: Tooling and script execution are limited to local Python scripts that utilize the standard library only, avoiding risks associated with external dependencies or untrusted remote code.- [INDIRECT_PROMPT_INJECTION]: The skill interacts with untrusted data by auditing local codebase files and scanning external URLs for privacy compliance. While this presents an indirect prompt injection surface, the risk is addressed by the 'Security & Multi-Agent Hygiene' protocol which requires treating all external data as hostile. The capabilities involved (file read/search, local script execution, and documentation generation) are necessary for the skill's primary functions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 07:35 AM
Security Audit — agent-trust-hub — legal-finance