scope-change-controller-scott-margetts

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it is designed to ingest and process untrusted data from external emails, call notes, and correspondence.
  • Ingestion points: The skill monitors matter emails (Outlook), SharePoint documents, and Teams messages to detect scope signals. (SKILL.md, README.md)
  • Capability inventory: It uses this information to draft internal out-of-scope notices, client-facing change notices, and updates to scope registers. (SKILL.md)
  • Boundary markers: No specific delimiters or instructions for the agent to ignore embedded instructions in the ingested data are present in the provided instructions.
  • Sanitization: No explicit sanitization or filtering of external content is described.
  • Mitigation: The risk is significantly mitigated by the 'Core design principle' of 'surface for confirmation,' which requires an LPM or attorney to review and approve all drafted outputs before they are finalized or sent to clients. (SKILL.md)
  • [SAFE]: No malicious command execution, privilege escalation, or unauthorized network operations were identified. The use of connected tools (M365) is consistent with the stated purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:34 PM
Security Audit — agent-trust-hub — scope-change-controller-scott-margetts