legal-brainstorming

Warn

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill uses strong directives like '不可覆寫' (cannot be overwritten) and '最高優先' (highest priority) to enforce specific usage restrictions, which utilize patterns typically associated with overriding agent behavioral constraints.- [REMOTE_CODE_EXECUTION]: Instructions direct the agent to install the 'mcp-taiwan-legal-db' package and register a remote MCP server at 'https://tlr.dr-lawbot.com/mcp'. Installing software from unverifiable sources and connecting to third-party tool servers allows for the potential execution of external code or logic.- [COMMAND_EXECUTION]: The agent is instructed to use shell commands such as 'pip install' and platform configuration tools (e.g., 'claude mcp add') to modify the user's environment and application configuration files.- [EXTERNAL_DOWNLOADS]: The skill depends on external resources, including a Python package and a remote HTTP service, which are not hosted by trusted vendors or well-known providers.- [PROMPT_INJECTION]: The skill ingests untrusted user input describing case facts and legal documents. It lacks boundary markers or input sanitization, creating a surface for indirect prompt injection where malicious data could influence the agent's downstream actions or tool calls.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 5, 2026, 11:15 PM
Security Audit — agent-trust-hub — legal-brainstorming