skills/matematicsolutions/awesome-matematic-skills-pl/adversarial-legal-review-pl/Gen Agent Trust Hub
adversarial-legal-review-pl
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill acts as a processing engine for high-stakes legal documents (untrusted external data). While this creates an attack surface where instructions hidden within a legal document could attempt to influence the agent, the multi-agent 'adversarial' structure (Builder vs. Attacker) and the mandatory 10-point verification checklist serve as inherent architectural mitigations against simple injection attempts.
- [EXTERNAL_DOWNLOADS]: The skill references external resources including the Microsoft Agent Governance Toolkit and the 'lavern' blueprint. These references are used for attribution and comparative security analysis (PromptDefense) and do not involve the execution of untrusted code. All referenced tools for legal research (SAOS, ISAP, EU SPARQL) are specialized professional services.
- [COMMAND_EXECUTION]: The skill requests 'Read' and 'Write' tools to interact with local files. These are used for the intended purpose of analyzing and reporting on legal documents within the local environment as specified by the 'data-residency: local' policy.
- [DATA_EXFILTRATION]: No exfiltration patterns were found. The skill explicitly suggests using a pseudonymization tool ('let-it-be') for sensitive documents and specifies 'pii-egress: none' in its configuration.
Audit Metadata