contract-review

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill integrates with well-known communication and document management services (Yandex 360, Diadoc, SBIS) to fetch contracts for review. It includes specific safety instructions that limit the scope of data access to relevant documents and strictly forbid the agent from performing unauthorized actions, such as signing or modifying documents.
  • [PROMPT_INJECTION]: Because the skill processes untrusted text from external contracts, it is exposed to potential indirect prompt injection attacks. While no specific boundary markers are defined for the input text, the skill's instructions mitigate this risk by requiring the agent to provide exact quotes from the document and to emphasize that the final output must be reviewed by a qualified lawyer.
  • Ingestion points: Contract files (PDF/DOCX) via the main skill body, email content/attachments (reference/gmail-fetch.md), and EDI documents (reference/docusign-fetch.md).
  • Boundary markers: Not specified.
  • Capability inventory: Tools for file system access, document retrieval from external platforms, and Word document generation.
  • Sanitization: No explicit input sanitization is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 06:56 PM
Security Audit — agent-trust-hub — contract-review