advogado-especialista
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-supplied legal case information through a multi-step workflow. It is configured to use powerful tools such as
claude-codeandcursorwhich often possess shell execution capabilities. The absence of explicit boundary markers or instructions to ignore commands embedded in user-provided documents creates a surface for indirect prompt injection. \n - Ingestion points: User-provided details regarding "advogado", "direito", and "processo judicial" as defined in the skill's trigger sections. \n
- Boundary markers: None identified. There are no instructions defining delimiters or warning the agent to ignore embedded instructions in case data. \n
- Capability inventory: The skill allows use of
claude-code,cursor,gemini-cli,codex-cli, andantigravity. \n - Sanitization: No validation or sanitization logic is provided for external inputs. \n- [METADATA_POISONING]: The skill documentation includes self-asserted safety claims such as
risk: safeandAuditoria: Validada por skill-sentinel. These assertions are data to be evaluated and should not be treated as authoritative claims about the skill's actual safety profile.
Audit Metadata