sanctions-screening-legal-analysis-skill-english-gillan-saleh

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions are entirely focused on its stated purpose of sanctions screening and legal analysis. There are no indications of malicious intent.
  • [PROMPT_INJECTION]: The skill contains strong directives ('ABSOLUTE RULE') intended to prevent AI hallucinations and ensure data accuracy. These are defensive in nature and do not attempt to bypass system safety guidelines or extract sensitive information.
  • [EXTERNAL_DOWNLOADS]: The agent is instructed to use web search and fetch tools to access official government and international organization websites (such as ofac.treas.gov, eur-lex.europa.eu, and gov.uk). These are well-known and appropriate sources for the skill's functionality.
  • [COMMAND_EXECUTION]: The skill references the use of 'OpenLegi' (a tool for accessing French law) and standard web tools. No arbitrary or dangerous shell command execution was found.
  • [DATA_EXFILTRATION]: No evidence of hardcoded credentials, access to sensitive local files (like .ssh or .env), or transmission of private data to unauthorized domains was detected.
  • [INDIRECT_PROMPT_INJECTION]: As the skill processes user-supplied names and external web content, it possesses a standard attack surface for indirect prompt injection. However, the instructions include specific guidance on handling ambiguous names and verification, which serves as a mitigation for processing untrusted data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — sanctions-screening-legal-analysis-skill-english-gillan-saleh