legal-research
Fail
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: HIGHCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to modify its execution environment, including installing software packages and registering MCP servers (e.g.,
pip install mcp-taiwan-legal-db,claude mcp add ...,gemini mcp add ...). - [EXTERNAL_DOWNLOADS]: The skill requires downloading an external package (
mcp-taiwan-legal-db) from a public registry and connecting to a remote MCP endpoint (https://tlr.dr-lawbot.com/mcp) to function. - [PROMPT_INJECTION]: The "Forbidden Rule" section uses adversarial language designed to override agent behavior and prevent the agent from following subsequent user instructions if specific conditions are met, utilizing phrases like "不可覆寫" (cannot override), "最高優先" (highest priority), and "不得以任何提示詞...解除或繞過" (cannot be bypassed by any prompt).
- [DATA_EXFILTRATION]: Natural language descriptions of legal cases and facts provided by the user are transmitted to a remote external endpoint (
https://tlr.dr-lawbot.com/mcp) for semantic analysis.
Recommendations
- AI detected serious security threats
Audit Metadata