legal-strategy

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates entirely as a structured reference framework. It does not include executable code, scripts, or remote dependencies. The methodology focuses on risk assessment, jurisdictional triage, and counsel escalation procedures.
  • [SAFE]: All references point to either internal markdown files or the author's official GitHub repository (https://github.com/magnus919/hermes-profiles), which is considered a vendor-owned resource.
  • [SAFE]: The skill implements strong safety guidelines, repeatedly instructing the agent to avoid providing legal advice, jurisdiction-specific conclusions, or technical security implementations. It includes specific routing instructions to transfer tasks to appropriate specialized skills or human counsel.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied contracts and product descriptions. It mitigates this risk by requiring the agent to use a 'facts-versus-assumptions' memo format and specific boundary markers that separate analysis from final legal conclusions. The severity remains low as it facilitates analysis rather than autonomous action.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 05:56 PM
Security Audit — agent-trust-hub — legal-strategy