contract-review-pro
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes
subprocess.runto execute local binaries includingpandoc(for document text extraction) andmmdc(Mermaid CLI for rendering diagrams). These operations are implemented using list-based arguments which mitigate shell injection risks. The utilities are standard for the skill's stated purpose of document analysis and visualization. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user-provided contract files (.docx). While this is an inherent attack surface for indirect prompt injection, the skill's methodology relies on a strict four-layer review checklist and structured comment generation, which constrains the agent's interpretation of the input data and mitigates the risk of executing instructions embedded within the contracts.
- [DATA_EXFILTRATION]: No unauthorized network activity or data exfiltration patterns were detected. The skill instructions suggest using standard Web Search or specific MCP tools for entity verification (Layer 0), which is a legitimate part of the professional contract review workflow.
- [DYNAMIC_EXECUTION]: The skill utilizes
defusedxmlfor XML parsing in its OOXML manipulation scripts. This is a security best practice that protects the environment from XML External Entity (XXE) attacks when processing potentially malicious document structures.
Audit Metadata