adversarial-legal-review-pl

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes high-stakes legal documents (opinions, memos, M&A deliverables) which serve as untrusted external data. While the workflow includes a verification stage, there are no explicit boundary markers or instruction-filtering mechanisms defined for the ingested text.
  • Ingestion points: User-provided legal deliverables.
  • Boundary markers: None specified in the instructions.
  • Capability inventory: Uses "Read" and "Write" tools for local file management.
  • Sanitization: Recommends pseudonimization for professional secrecy but does not implement prompt-injection-specific sanitization.
  • [EXTERNAL_DOWNLOADS]: The skill documentation references external projects on GitHub, specifically the Microsoft Agent Governance Toolkit and the AnttiHero/lavern project. These URLs are provided for methodological attribution and security context, referring to well-known and reputable organizations.
  • [SAFE]: The skill implements a robust self-audit mechanism, including a deterministic scoring system and a "Panel of Dissent" for resolving interpretative conflicts. It adheres to data residency requirements and provides clear guidance on professional secrecy and RODO compliance.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 08:27 AM
Security Audit — agent-trust-hub — adversarial-legal-review-pl