matter-plan-builder-scott-margetts

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behavior or high-risk patterns were detected. The skill is designed to facilitate legal project management by structuring plans and assigning ownership.\n- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface due to its core function of ingesting and analyzing untrusted correspondence data.\n
  • Ingestion points: Processes project scope summaries, engagement letters, SharePoint documents, and Outlook emails (as specified in SKILL.md and README.md).\n
  • Boundary markers: The instructions use structured field mapping for internal data but do not implement explicit delimiters or 'ignore' instructions for arbitrary text from external correspondence.\n
  • Capability inventory: The skill can create files (.docx, .csv, .json) and perform data retrieval through the M365 MCP connector.\n
  • Sanitization: There are no instructions for sanitizing or escaping the content of processed correspondence before processing.\n Note: This configuration is considered a low-risk, expected byproduct of the skill's primary utility and does not elevate the security verdict.\n- [SAFE]: M365 Connected Mode functionality is described as utilizing native platform MCP connectors for searching and retrieving documents, which is consistent with standard AI agent platform capabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:34 PM
Security Audit — agent-trust-hub — matter-plan-builder-scott-margetts