generic-legal-ops
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions define an attack surface for indirect prompt injection.
- Ingestion points: In the "Meeting Briefings" section, the agent is instructed to "Gather context from connected sources" including external communications like "Email (recent correspondence)" and "Chat (recent discussions)," as well as "Documents."
- Boundary markers: The skill lacks instructions for the agent to use specific delimiters or to disregard potentially conflicting instructions embedded within the external data sources during analysis.
- Capability inventory: The skill's workflow involves reading local configuration files (negotiation playbooks), accessing communication logs (email/chat), and synthesizing findings into briefings and templates, providing a pathway for malicious content to influence agent outputs.
- Sanitization: No guidelines are provided for validating or sanitizing content retrieved from external sources before it is processed into the legal operations workflow.
- [NO_CODE]: The skill consists solely of Markdown-based instructions and response templates for the agent. It does not include any executable scripts, binaries, or automated installation steps, which reduces the risk of direct code-based attacks.
Audit Metadata