founder-agreement-drafting-stephane-boghossian

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because its primary functions involve processing and auditing user-provided legal documents (Review Mode and Conflict Triage phases).\n
  • Ingestion points: User-provided legal agreement drafts or specific clause text pasted into the agent context (File: SKILL.md).\n
  • Boundary markers: Absent. The skill instructions do not define specific delimiters (e.g., XML tags or unique markers) to isolate user-provided data from the system prompt.\n
  • Capability inventory: The skill allows the use of standard file operations (Read/Write/Edit) and network tools (WebFetch/WebSearch).\n
  • Sanitization: Absent. There is no explicit logic for sanitizing or filtering instructions that might be embedded within the legal documents provided by a user.\n- [SAFE]: The skill incorporates a mandatory 'Scope Gate' and clear operating principles that explicitly define the agent's limitations, warn users against treating output as legal advice, and provide clear guidance to remain a neutral drafting assistant. These self-imposed constraints serve as significant guardrails against unintended behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — founder-agreement-drafting-stephane-boghossian