contract-analysis

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses established ServiceNow MCP tools and REST APIs to manage contract data. All operations are confined to the ServiceNow ecosystem.
  • [SAFE]: No evidence of credential exposure, data exfiltration to external domains, or malicious command execution was found. The use of placeholders for record identifiers follows security best practices.
  • [SAFE]: The skill's behavior is entirely consistent with its stated purpose as a contract analysis tool for legal services.
  • [PROMPT_INJECTION]: The skill ingests untrusted contract text from the sys_attachment table (Ingestion point). While no explicit boundary markers or sanitization are defined in the instructions, the skill's capabilities are limited to record creation and updates within ServiceNow (Capability inventory: SN-Create-Record, SN-Update-Record). The requirement for review by authorized legal roles serves as a primary control against adversarial data content.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:34 PM
Security Audit — agent-trust-hub — contract-analysis