local-first-legal-workspace
Pass
Audited by Gen Agent Trust Hub on Jul 8, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions and configuration files. It contains no executable scripts, binaries, or automated network commands.
- [NO_CODE]: The skill provides instructional guidance and templates for manual or AI-assisted auditing but does not include any source code or dependencies.
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data such as third-party codebases and architecture diagrams, which constitutes an indirect prompt injection surface. The risk is minimized as the skill lacks automated execution or writing capabilities and provides specific instructions for the agent to verify evidence and avoid absolute claims.
- Ingestion points: SKILL.md (Code/runtime evidence mode, User-supplied architecture mode).
- Boundary markers: Absent.
- Capability inventory: None (the skill generates text reports and does not specify subprocess, file-write, or network operations).
- Sanitization: Absent.
Audit Metadata