contract-redline

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external content (legal contracts), creating a potential surface for indirect prompt injection attacks where malicious instructions could be embedded within a document.\n
  • Ingestion points: The skill reads entire contract documents as defined in SKILL.md.\n
  • Boundary markers: Absent; there are no instructions to use specific delimiters or to ignore embedded natural language commands within the processed contracts.\n
  • Capability inventory: The skill itself does not specify scripts or subprocess operations, but relies on the agent's general toolset.\n
  • Sanitization: Absent; no filtering or sanitization of the contract text is mandated before the agent performs its review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:23 AM
Security Audit — agent-trust-hub — contract-redline