severability-general
Pass
Audited by Gen Agent Trust Hub on Feb 21, 2026
Risk Level: SAFE
Full Analysis
- [Indirect Prompt Injection] (SAFE): The skill processes user-provided contracts, which represents a surface for indirect prompt injection.
- Ingestion points: User uploads or pastes contracts as described in
SKILL.md. - Boundary markers: Absent; the agent does not use specific delimiters to isolate user text from its own instructions.
- Capability inventory: No subprocess calls, network operations, or file system write capabilities found in any scripts.
- Sanitization: Absent.
- Conclusion: While the surface exists, there are no dangerous capabilities for an attacker to exploit via injected text.
Audit Metadata