legal
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill is composed exclusively of Markdown instructions and regulatory reference materials.
- [SAFE]: The skill handles potentially sensitive information such as contracts and NDAs, but it lacks any tools or commands for data exfiltration, credential harvesting, or unauthorized network access.
- [PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection because it processes untrusted data such as legal contracts and user-supplied compliance queries. This risk is assessed as safe/negligible because the skill does not possess any high-risk capabilities like shell execution, file modification, or network operations. Furthermore, the skill explicitly includes a failure-mode reference file designed to mitigate LLM hallucinations and overconfidence in legal contexts. Ingestion points: SKILL.md (Phase 1: INTAKE) and references/contract-review.md. Boundary markers: Absent. Capability inventory: No dangerous capabilities detected. Sanitization: Absent.
Audit Metadata