legal-service-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions include a URL for downloading the SKILL.md file from a GitHub repository owned by the author. This is a standard practice for skill deployment and uses a well-known hosting service.
  • [NO_CODE]: No scripts, executables, or code dependencies are present in the skill files, which eliminates the risk of malicious code execution.
  • [PROMPT_INJECTION]: The skill's functionality includes analyzing user-supplied documents, creating an indirect prompt injection surface. However, the lack of dangerous capabilities (such as network or file access) renders this risk minimal. 1. Ingestion points: User-provided contract text and legal descriptions in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: No tools for network, file, or system execution are used. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 20, 2026, 01:54 PM
Security Audit — agent-trust-hub — legal-service-advisor