messaging-compliance-checker
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is a non-executable markdown document. It does not contain any scripts, binary files, or commands that could be executed on the host system.
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it is designed to ingest and process untrusted 'Copy text' provided by users.
- Ingestion points: The 'Copy text' input field in SKILL.md.
- Boundary markers: None present; the skill does not instruct the agent to use delimiters like XML tags or triple quotes to isolate the content being reviewed.
- Capability inventory: The agent generates a structured textual 'COMPLIANCE REVIEW' verdict.
- Sanitization: No sanitization or validation of the input text is specified.
- [SAFE]: The external link to the author's GitHub repository (github.com/sboghossian/mini-claude-for-legal) is a standard attribution reference and does not involve remote code execution or data exfiltration.
Audit Metadata