contract-review-pro
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill executes external system utilities to perform specialized document processing tasks. These operations are performed using safe invocation methods (passing arguments as lists) to prevent command injection.
- In
scripts/contract_analyzer.py, it usespandocto extract plain text from Word documents for analysis. - In
scripts/mermaid_renderer.py, it uses the Mermaid CLI (mmdc) to render business flowcharts into image files. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from contract documents (.docx files) to perform its primary function of legal and business review. This creates an attack surface where malicious text within a contract could attempt to influence the AI agent's behavior during the review process.
- Ingestion points: Contract text is ingested via
scripts/contract_analyzer.py(text extraction) andscripts/workflow.py(OOXML unpacking). - Boundary markers: The skill uses a highly structured methodology defined in
SKILL.mdandreferences/checklist.mdto constrain the AI's analysis to specific legal and business criteria. - Capability inventory: The skill possesses capabilities to write to the local file system (saving reviewed documents and reports) and execute specific CLI tools (
pandoc,mmdc). It does not perform arbitrary network requests. - Sanitization: The skill employs
defusedxml.ElementTreeanddefusedxml.minidomfor all XML parsing, providing protection against XML External Entity (XXE) attacks. - [EXTERNAL_DOWNLOADS]: The skill documentation refers to standard external tools and libraries required for its workflow, such as
pandocand the Mermaid CLI (@mermaid-js/mermaid-cli). These are well-known, legitimate software components used for document conversion and diagram rendering.
Audit Metadata