ai-agent-contract-language-pack
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from external sources, including 'approved commercial positions and governing documents', 'measured operating evidence', and 'telemetry'. These ingestion points (identified in SKILL.md under the 'Inputs' and 'Workflow' sections) represent a surface for indirect prompt injection. While no explicit boundary markers or sanitization logic are defined to mitigate this risk, the skill lacks high-impact capabilities (such as network operations or file system writes) that would allow for severe exploitation beyond influencing the generated contract text.
- [NO_CODE]: The analyzed skill consists entirely of instructional markdown and does not include any scripts, executables, or code-based logic.
Audit Metadata