contract-redliner
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted contract data from files or URLs which creates a potential attack surface for indirect prompt injection. 1. Ingestion points: Contract text is ingested via files or URLs as described in the SKILL.md workflow. 2. Boundary markers: The instructions do not define delimiters or specific instructions to ignore embedded commands within the contract text. 3. Capability inventory: The skill has access to Bash, Write, Read, Glob, and Grep tools, allowing for file system and potentially network operations. 4. Sanitization: No sanitization or validation of the input text is specified before it is processed by the agent.
Audit Metadata