legal-client-intake
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill does not contain any instructions to override safety filters, bypass system constraints, or extract internal prompts. It includes professional constraints that reinforce safety, such as the explicit instruction to never provide legal advice.
- [DATA_EXFILTRATION]: There are no network operations, API calls, or commands that could exfiltrate data. While the skill handles prospect information, it provides no mechanism to send this data to external or untrusted domains.
- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or sensitive credentials were found in the instructions or metadata.
- [REMOTE_CODE_EXECUTION]: The skill consists entirely of markdown instructions. It does not include any scripts, package managers (pip, npm), or commands that download and execute remote code.
- [COMMAND_EXECUTION]: No shell commands, subprocess calls, or administrative privilege requests are present in the skill.
- [OBFUSCATION]: The content is written in clear, plain language. No Base64, hex encoding, zero-width characters, or other hidden content techniques were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted prospect data. While it lacks explicit boundary markers (e.g., delimiters) for this data, it also lacks any executable capabilities or network access that could be exploited via an indirect injection attack.
- [NO_CODE]: The skill is purely instructional and does not ship with any accompanying scripts or configuration files that execute logic.
Audit Metadata