outsourcing-contract
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes a local Python script located at
{REPO_DIR}/shared/docx-generator.pyto convert generated contract text into.docxformat. This operation is restricted to the skill's local repository environment and is a primary feature for document output. - [PROMPT_INJECTION]: The skill includes functionality to analyze existing contracts provided by the user. This represents an indirect prompt injection surface where malicious instructions could be embedded in the analyzed text. The instructions do not specify the use of strict boundary markers to isolate this untrusted content from the agent's core instructions.
- [SAFE]: External references are limited to an informational link to a Discord community for the 'SpeciAI' hub. No unauthorized network operations, exfiltration patterns, or obfuscated content were found.
Audit Metadata