eccc-jeanne-sulzer

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the retrieval of legal documents and foundational frameworks from official and highly reputable domains, including eccc.gov.kh (the official court site), legal-tools.org (ICC Legal Tools), and un.org (United Nations). These references are legitimate and target well-known, trusted organizations.
  • [PROMPT_INJECTION]: Analysis of the instructional content in SKILL.md and its associated reference files reveals no evidence of adversarial prompting, role-play bypasses, or instructions intended to override system safety guidelines.
  • [DATA_EXFILTRATION]: No access to sensitive user files, environment variables, or credentials was identified. Network operations are strictly scoped to the retrieval of public court records.
  • [REMOTE_CODE_EXECUTION]: The skill does not include any executable scripts, package dependencies, or patterns that would lead to the execution of remote code or runtime compilation.
  • [SAFE]: The skill is a collection of non-executable markdown instructions and reference materials. It introduces an ingestion surface for indirect prompt injection by analyzing user-supplied legal documents, but this is handled without high-privilege tools or dangerous capabilities, posing no significant security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:32 PM
Security Audit — agent-trust-hub — eccc-jeanne-sulzer