legal-briefing

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process and summarize content from external sources which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The 'Phase 3: Assemble Context' section of SKILL.md directs the agent to gather data from Email Systems, Messaging Platforms (Slack, Teams), and Document Repositories (SharePoint, Box, Egnyte).
  • Boundary markers: The briefing instructions do not include specific delimiters or directives to the agent to ignore or isolate instructions that may be embedded within the gathered external content.
  • Capability inventory: No executable scripts are provided within the skill itself, but the instructions assume the agent has access to integrated tools for reading private and external communication channels.
  • Sanitization: The workflow lacks explicit steps for sanitizing, filtering, or validating the content retrieved from these external systems before it is incorporated into the briefing document.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 01:23 AM
Security Audit — agent-trust-hub — legal-briefing