legal-contract-review
Pass
Audited by Gen Agent Trust Hub on Jul 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's logic is focused on legal analysis and text generation. No unauthorized file access, network communication, or administrative privilege requests were detected.- [PROMPT_INJECTION]: Analysis of indirect prompt injection surfaces:
- Ingestion points: The skill processes untrusted user-uploaded contracts and legal texts in SKILL.md and references/contract-reviewer/guide.md.
- Boundary markers: The skill does not implement explicit delimiters or 'ignore' instructions for embedded data.
- Capability inventory: No dangerous capabilities such as network requests, file-system writes, or code execution tools are present in the provided files.
- Sanitization: No sanitization or escaping of input text is performed.
- Conclusion: While an ingestion surface exists, the lack of exploitable capabilities prevents harmful outcomes.
Audit Metadata