legal-translation

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it is designed to ingest and process untrusted external data from uploaded legal documents.
  • Ingestion points: SKILL.md (File Handling section) specifies processing uploaded PDF and DOCX files.
  • Boundary markers: While the skill requires structured outputs and safety watermarks, it lacks explicit instructions to ignore instructions embedded within the source documents.
  • Capability inventory: The agent utilizes pdf-reading, docx, and pdf skills to handle files.
  • Sanitization: No explicit filtering of source document content is performed.
  • [SAFE]: The skill includes extensive professional disclaimers, a 'Delegation Gate', and mandatory watermarking (⚠ DRAFT) to ensure users are aware that outputs require legal review.
  • [SAFE]: No evidence of malicious behavior, credential harvesting, or unauthorized network access was detected in the skill code or reference materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 08:53 AM
Security Audit — agent-trust-hub — legal-translation