legal-document-drafting-formatting-alessandro-dardano

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data which presents a theoretical surface for indirect prompt injection.
  • Ingestion points: The skill is designed to process user-provided substantive content, project knowledge, and uploaded .docx files as specified in SKILL.md and README.md.
  • Boundary markers: While the skill uses structured tracks for formatting, it does not explicitly define delimiters (e.g., XML tags or specific markers) to separate user-provided drafting instructions from the data within processed documents.
  • Capability inventory: The agent has the capability to perform searches in corporate repositories (SharePoint) and generate/modify Word documents using the docx skill.
  • Sanitization: No explicit sanitization or instruction to ignore embedded commands within ingested files is provided in the instructions.
  • [SAFE]: The skill demonstrates high-quality instructional design and professional standards. The technical snippets provided (Word XML and JavaScript) are legitimate methods for implementing document numbering and signature block atomicity. The use of corporate search tools is consistent with the stated purpose of assisting in-house counsel with existing precedents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — legal-document-drafting-formatting-alessandro-dardano