vendor-contract-risk-review

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to ingest and process external contract text or documents provided by the user. This creates a potential surface where malicious instructions could be embedded within a contract draft to influence the agent's behavior. However, the risk is mitigated by the skill's specific focus on structured analysis (finding specific clauses like 'Auto-renewal' or 'Liability caps') and its explicit guardrails that limit the agent's output to risk flagging rather than code execution or administrative tasks.
  • [Clear Scope and Guardrails]: The instructions explicitly forbid the agent from providing legal advice or drafting final legal language, which helps prevent the misuse of the agent's capabilities in high-stakes environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 11:55 PM
Security Audit — agent-trust-hub — vendor-contract-risk-review