advogado-especialista

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-supplied legal case information through a multi-step workflow. It is configured to use powerful tools such as claude-code and cursor which often possess shell execution capabilities. The absence of explicit boundary markers or instructions to ignore commands embedded in user-provided documents creates a surface for indirect prompt injection. \n
  • Ingestion points: User-provided details regarding "advogado", "direito", and "processo judicial" as defined in the skill's trigger sections. \n
  • Boundary markers: None identified. There are no instructions defining delimiters or warning the agent to ignore embedded instructions in case data. \n
  • Capability inventory: The skill allows use of claude-code, cursor, gemini-cli, codex-cli, and antigravity. \n
  • Sanitization: No validation or sanitization logic is provided for external inputs. \n- [METADATA_POISONING]: The skill documentation includes self-asserted safety claims such as risk: safe and Auditoria: Validada por skill-sentinel. These assertions are data to be evaluated and should not be treated as authoritative claims about the skill's actual safety profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 08:35 PM
Security Audit — agent-trust-hub — advogado-especialista