collaboration-contract-intake
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill instructions are focused on administrative information gathering and do not contain any malicious patterns or obfuscation.
- [COMMAND_EXECUTION]: The skill utilizes Bash for benign organizational tasks. Evidence: The '手順' and 'Available Tools' sections specify using Bash for formatting tables and checklists.
- [EXTERNAL_DOWNLOADS]: The skill uses WebSearch and WebFetch for legitimate research purposes. Evidence: Available tools include WebSearch and WebFetch to verify counterparty public information or institutional policies.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection by reading external documents. 1. Ingestion points: Reads draft contracts, emails, and research plans as noted in the 'Required Inputs' and '手順' sections. 2. Boundary markers: None explicitly defined in the prompt templates. 3. Capability inventory: Writing files (intake forms, emails) and performing web searches/fetches. 4. Sanitization: Not explicitly present; the workflow relies on human-in-the-loop review by specialized departments.
Audit Metadata