fee-arrangement-structuring
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from external sources such as legal scope clauses, matter descriptions, and firm communications.
- Ingestion points: Multiple modes in SKILL.md (e.g., Mode 2 and Mode 5) take external text input for analysis.
- Boundary markers: The instructions do not specify any delimiters or safety prompts to prevent the agent from following instructions potentially embedded in the provided legal text.
- Capability inventory: The agent generates textual responses and formatted documents based on the untrusted input.
- Sanitization: No input validation or sanitization routines are defined in the skill.
- [NO_CODE]: The skill contains only markdown instructions and no executable scripts or external code dependencies, which significantly limits the potential for traditional technical exploits.
Audit Metadata