dpa-art28

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill package is composed exclusively of Markdown instructions, legal templates, and reference guides. It contains no executable scripts (Python, JS, Shell), binary files, or installation commands that could execute code on the host system.
  • [SAFE]: No network exfiltration or unauthorized communication was detected. The skill only references well-known and trusted external resources, such as the official EUR-Lex portal (eur-lex.europa.eu), which is documented as part of the legal reference material.
  • [SAFE]: There is no evidence of hardcoded credentials, API keys, or attempts to access sensitive local files (e.g., .ssh, .aws, or environment variables).
  • [SAFE]: The skill does not utilize dynamic context injection or command execution. All placeholders within the templates are for user-provided legal entities and dates, used strictly for contract generation.
  • [SAFE]: While the skill processes user-provided contract text for review, it lacks any dangerous tools (shell access, file-write outside context, or network) that would allow for the exploitation of indirect prompt injection. The skill provides clear, structured workflows and checklists that mitigate the risk of behavioral manipulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 08:53 AM
Security Audit — agent-trust-hub — dpa-art28