contract-review-pro

Pass

Audited by Gen Agent Trust Hub on Aug 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes subprocess.run to execute local binaries including pandoc (for document text extraction) and mmdc (Mermaid CLI for rendering diagrams). These operations are implemented using list-based arguments which mitigate shell injection risks. The utilities are standard for the skill's stated purpose of document analysis and visualization.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided contract files (.docx). While this is an inherent attack surface for indirect prompt injection, the skill's methodology relies on a strict four-layer review checklist and structured comment generation, which constrains the agent's interpretation of the input data and mitigates the risk of executing instructions embedded within the contracts.
  • [DATA_EXFILTRATION]: No unauthorized network activity or data exfiltration patterns were detected. The skill instructions suggest using standard Web Search or specific MCP tools for entity verification (Layer 0), which is a legitimate part of the professional contract review workflow.
  • [DYNAMIC_EXECUTION]: The skill utilizes defusedxml for XML parsing in its OOXML manipulation scripts. This is a security best practice that protects the environment from XML External Entity (XXE) attacks when processing potentially malicious document structures.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 29, 2026, 05:11 AM
Security Audit — agent-trust-hub — contract-review-pro