collaboration-contract-intake

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill instructions are focused on administrative information gathering and do not contain any malicious patterns or obfuscation.
  • [COMMAND_EXECUTION]: The skill utilizes Bash for benign organizational tasks. Evidence: The '手順' and 'Available Tools' sections specify using Bash for formatting tables and checklists.
  • [EXTERNAL_DOWNLOADS]: The skill uses WebSearch and WebFetch for legitimate research purposes. Evidence: Available tools include WebSearch and WebFetch to verify counterparty public information or institutional policies.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection by reading external documents. 1. Ingestion points: Reads draft contracts, emails, and research plans as noted in the 'Required Inputs' and '手順' sections. 2. Boundary markers: None explicitly defined in the prompt templates. 3. Capability inventory: Writing files (intake forms, emails) and performing web searches/fetches. 4. Sanitization: Not explicitly present; the workflow relies on human-in-the-loop review by specialized departments.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 03:36 AM
Security Audit — agent-trust-hub — collaboration-contract-intake