document-approval-tracker-scott-margetts
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process untrusted data from pasted email chains in Mode 2 and Mode 3 to reconstruct document status, creating a surface for indirect prompt injection.
- Ingestion points: Pasted email content provided by users in SKILL.md.
- Boundary markers: The skill instructions promote the use of an [APPROVAL TRACKER] prefix as a routing signal to separate external data from intent.
- Capability inventory: The skill produces text-based outputs including docx matter records and email drafts; it does not possess capabilities for subprocess execution or unauthorized file system writes.
- Sanitization: No technical sanitization or validation of the ingested email text is specified in the prompt logic.
- [SAFE]: The skill incorporates a mandatory 'Hard gate' requiring confirmation of matter and client identifiers before generating formal documentation, which serves as a security control against data misattribution.
- [SAFE]: The skill utilizes standard workflows for integration with established services such as Microsoft SharePoint, Outlook, and iManage.
Audit Metadata