mediation-dispute-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing untrusted external case materials, which creates a vulnerability to indirect prompt injection if those files contain malicious instructions.
  • Ingestion points: In SKILL.md, specifically under 'Mode B: Direct Analysis', the skill instructs the agent to read and extract information from uploaded files such as pleadings, written statements, contracts, correspondence (emails/letters), and evidence.
  • Boundary markers: The instructions lack boundary markers or specific delimiters (e.g., XML tags or triple quotes) to separate untrusted user data from the agent's core instructions, nor do they include warnings to ignore instructions embedded within the data.
  • Capability inventory: The agent has the capability to output complex analysis to the chat and to generate professional documents via an integrated document creation tool.
  • Sanitization: There are no instructions for sanitizing, escaping, or validating the content of the ingested files before they are processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 10:13 PM
Security Audit — agent-trust-hub — mediation-dispute-analysis