document-approval-tracker-scott-margetts

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process untrusted data from pasted email chains in Mode 2 and Mode 3 to reconstruct document status, creating a surface for indirect prompt injection.
  • Ingestion points: Pasted email content provided by users in SKILL.md.
  • Boundary markers: The skill instructions promote the use of an [APPROVAL TRACKER] prefix as a routing signal to separate external data from intent.
  • Capability inventory: The skill produces text-based outputs including docx matter records and email drafts; it does not possess capabilities for subprocess execution or unauthorized file system writes.
  • Sanitization: No technical sanitization or validation of the ingested email text is specified in the prompt logic.
  • [SAFE]: The skill incorporates a mandatory 'Hard gate' requiring confirmation of matter and client identifiers before generating formal documentation, which serves as a security control against data misattribution.
  • [SAFE]: The skill utilizes standard workflows for integration with established services such as Microsoft SharePoint, Outlook, and iManage.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:33 PM
Security Audit — agent-trust-hub — document-approval-tracker-scott-margetts