uk-disclosure-list-review

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process untrusted user-supplied documents (disclosure lists, pleadings, chronologies, witness statements), creating a surface for indirect prompt injection where instructions hidden in those documents could attempt to influence the agent's analysis.
  • Ingestion points: User-supplied disclosure lists, pleadings, chronologies, witness statements, and search records (referenced in SKILL.md).
  • Boundary markers: The skill does not define explicit delimiters to isolate untrusted data from system instructions.
  • Capability inventory: The skill utilizes file reading and browser/web search capabilities to retrieve legal authorities and rules (referenced in SKILL.md).
  • Sanitization: No specific sanitization or content filtering is mentioned for the ingested documents.
  • [NO_CODE]: The skill consists exclusively of Markdown instructions and YAML configuration files. There are no executable scripts (Python, JavaScript, shell) or binary files included, significantly reducing the attack surface for traditional malware, remote code execution, or persistence mechanisms.
  • [SAFE]: The skill's external network operations are restricted to retrieving legal rules, court orders, and authorities from reputable repositories (e.g., BAILII), which is consistent with its stated professional purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 08:53 AM
Security Audit — agent-trust-hub — uk-disclosure-list-review