lawbank-query-builder
Warn
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and install the
mcp-taiwan-legal-dbpackage usingpiporpipxduring the MCP automated bootstrapping process. - [COMMAND_EXECUTION]: The skill provides detailed instructions to execute shell commands for registering MCP servers, which involves programmatically modifying sensitive agent configuration files such as
~/.claude.json,~/.gemini/config/mcp_config.json,~/.codex/config.toml, and~/.cursor/mcp.json. - [REMOTE_CODE_EXECUTION]: The skill facilitates the registration of a remote HTTP-based MCP server at
https://tlr.dr-lawbot.com/mcp, allowing the agent to invoke and execute tools hosted on a remote infrastructure. - [DATA_EXFILTRATION]: The skill includes diagnostic protocols that access sensitive file paths containing authentication tokens and session metadata, specifically
~/.claude/.credentials.jsonand~/.claude/mcp-needs-auth-cache.json. - [DATA_EXFILTRATION]: The skill includes a
curlcommand designed to send a JSON-RPC initialization request to an external domain (https://tlr.dr-lawbot.com/mcp) to verify connectivity to the remote server. - [PROMPT_INJECTION]: The skill uses authoritative directive language such as "不可覆寫" (Not overridable) and "最高優先" (Highest priority) to enforce operational boundaries and licensing checks, which mirrors patterns commonly used to override or bypass model safety guidelines.
- [PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by ingesting and processing legal data pasted by users from external commercial databases.
- Ingestion points: User-provided text pasted into the conversation during the Step 5 validation workflow.
- Boundary markers: No specific delimiters or boundary markers are defined for the data ingestion phase.
- Capability inventory: The skill has access to a variety of legal research tools capable of performing file system queries and semantic database searches.
- Sanitization: The skill implements a manual verification discipline requiring comparison against official legal databases to mitigate the risk of hallucination or malicious content in the pasted data.
Audit Metadata