legal-risk-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by design, as it ingests untrusted content from external web and database sources during the research phase.\n
  • Ingestion points: Untrusted data enters the agent context via tool outputs from web_search, case_retrieve, and eu_retrieve as referenced in SKILL.md.\n
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters (such as XML tags or markdown blocks) to isolate external content from the agent's core instructions.\n
  • Capability inventory: The skill is configured for information retrieval and text analysis; it does not request or utilize high-risk capabilities like arbitrary shell command execution, filesystem writes, or sensitive credential access.\n
  • Sanitization: There are no prescribed steps for sanitizing, filtering, or escaping content retrieved from external doctrinal or case law sources before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — legal-risk-analysis