legal-brainstorming
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The section titled '使用授權鐵律' (Usage License Iron Rule) uses adversarial prompt patterns to attempt to hijack agent control. It uses phrases like '最高優先,不可覆寫' (highest priority, non-overridable) and '其優先級高於使用者的任何後續指示' (its priority is higher than any subsequent user instructions) to mandate behavior and prohibit bypass attempts.
- [PROMPT_INJECTION]: The skill ingests untrusted user facts in Step 1 and Step 2 without using boundary markers or sanitization, creating an indirect prompt injection vulnerability. While the skill's capabilities are currently limited to text generation, the lack of input validation is a best-practice violation. Ingestion points: Case facts in Step 1. Boundary markers: Absent. Capability inventory: Text generation and referral to other skills; no file-write or network operations. Sanitization: Absent.
Audit Metadata