matter-intake-scoping-scott-margetts

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill operates through natural language instructions and structured templates, focusing on legal project management workflows. No executable scripts, binary files, or obfuscated content are included.- [PROMPT_INJECTION]: The skill processes unstructured client data (emails, RFP documents, discovery notes), which is an inherent surface for indirect prompt injection. The skill mitigates this by instructing the agent to use source attribution and confidence labeling to separate data points. * Ingestion points: Client emails, discovery call notes, and data room contents described in SKILL.md. * Boundary markers: Uses source citations (e.g., [S1], [S2]) and confidence labels (Confirmed, Inferred, Unknown) to structure processed data. * Capability inventory: Generates matter records in .docx format and searches internal Microsoft 365 systems (Outlook, SharePoint, Teams) via platform connectors. * Sanitization: Relies on agent-internal safety filters and the documented confidence layering methodology to manage untrusted content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:33 PM
Security Audit — agent-trust-hub — matter-intake-scoping-scott-margetts