legaltech-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified in the skill instructions or reference code. The content is professional, domain-specific, and uses standard libraries.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze external legal documents (contracts, e-discovery files), which is an inherent ingestion surface for potentially untrusted data.
  • Ingestion points: Document text and metadata are ingested for parsing and risk analysis in references/EXAMPLES.md.
  • Boundary markers: The instructions do not specify the use of delimiters or provide the agent with explicit instructions to ignore commands that may be embedded within documents.
  • Capability inventory: The skill is configured with Bash, Read, Write, and WebSearch tools, providing a broad capability set.
  • Sanitization: The implementation uses regular expressions for feature extraction but does not include specific logic to sanitize or filter potential instructions found in the document text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — legaltech-expert