contract-qa

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill package consists entirely of Markdown instructions (SKILL.md), reference guides (reference/), and worked examples (examples/). No Python scripts, JavaScript files, binaries, or other executable assets are included in the distribution.
  • [SAFE]: The skill includes proactive security and compliance measures. The 'Privilege and legal use' section in SKILL.md explicitly instructs the agent to confirm the confidentiality status of documents before processing and clarifies that outputs are not legally privileged until adopted by an attorney.
  • [PROMPT_INJECTION]: The skill presents a potential surface for Indirect Prompt Injection because it is designed to ingest and process untrusted document content.
  • Ingestion points: The document input field defined in the SKILL.md frontmatter.
  • Boundary markers: Absent; the prompt instructions do not specify the use of delimiters or 'ignore embedded instructions' markers when interpolating document text.
  • Capability inventory: None; across all files, there are no subprocess calls, eval/exec patterns, file-system write operations, or network-enabled tools.
  • Sanitization: None; the instructions do not describe any methods for filtering or escaping content from the processed documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 08:53 AM
Security Audit — agent-trust-hub — contract-qa