brand-legal-review
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it ingests and analyzes external data. 1. Ingestion points: The skill is designed to review user-provided 'public statements and policy documents' as defined in the SKILL.md body. 2. Boundary markers: No explicit delimiters or boundary instructions are used to separate untrusted document content from the agent's instructions. 3. Capability inventory: The skill is limited to generating text-based reviews and does not have access to tools for file system modification, network requests, or subprocess execution. 4. Sanitization: No sanitization, escaping, or validation of the input text is mentioned. While the vulnerability is present, the lack of dangerous capabilities limits the potential impact of an exploit.
Audit Metadata