contract-redline
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external content (legal contracts), creating a potential surface for indirect prompt injection attacks where malicious instructions could be embedded within a document.\n
- Ingestion points: The skill reads entire contract documents as defined in SKILL.md.\n
- Boundary markers: Absent; there are no instructions to use specific delimiters or to ignore embedded natural language commands within the processed contracts.\n
- Capability inventory: The skill itself does not specify scripts or subprocess operations, but relies on the agent's general toolset.\n
- Sanitization: Absent; no filtering or sanitization of the contract text is mandated before the agent performs its review.
Audit Metadata