representations-and-warranties-mergers

Pass

Audited by Gen Agent Trust Hub on Feb 21, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill is designed to ingest and analyze untrusted external data (legal contracts), which creates a surface for indirect prompt injection attacks where malicious instructions could be embedded in the text to manipulate the agent's output.
  • Ingestion points: SKILL.md Step 2 (Analysis) and Step 3 (Drafting) involve processing user-provided contract text.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters (e.g., XML tags or triple backticks) to separate untrusted contract text from the system instructions.
  • Capability inventory: SAFE. The skill lacks any dangerous capabilities; it cannot execute commands, access the network, write to the filesystem, or call external APIs.
  • Sanitization: Absent. There is no logic provided to sanitize or filter instructions from the input text before processing.
  • [No Code] (SAFE): The skill consists entirely of Markdown instructions and reference templates. No scripts (Python, JavaScript, etc.) or executables are included, eliminating risks associated with malicious code execution or dependency vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 21, 2026, 11:46 AM
Security Audit — agent-trust-hub — representations-and-warranties-mergers