legal-request-triage

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it processes and acts upon untrusted data from ServiceNow legal requests.\n
  • Ingestion points: The agent is instructed to analyze the short_description and description fields from the sn_legal_request table in SKILL.md.\n
  • Boundary markers: Absent. There are no delimiters or instructions to ignore or isolate instructions that might be embedded within the legal request text.\n
  • Capability inventory: The agent has the authority to update legal requests (SN-Update-Record), create new legal cases, and append work notes (SN-Add-Work-Notes).\n
  • Sanitization: Absent. The skill does not define any steps to validate or sanitize the incoming text before it is used for classification and prioritization decisions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:34 PM
Security Audit — agent-trust-hub — legal-request-triage