legal-discovery

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate analysis of legal technology pipelines. While it targets sensitive data such as PII and legal documents, it does so within the scope of its stated purpose for auditing and compliance verification.
  • [PROMPT_INJECTION]: The skill processes untrusted codebase data via the $ARGUMENTS parameter, which presents a surface for indirect prompt injection.
  • Ingestion points: The skill reads various configuration files (package.json, requirements.txt, etc.) and source code across all phases of the audit.
  • Boundary markers: Absent; there are no specific markers or instructions to isolate or ignore embedded commands within the ingested data.
  • Capability inventory: The skill has extensive file system read capabilities and the ability to append telemetry logs to ~/.claude/projects/.
  • Sanitization: No sanitization of the ingested content is performed before processing.
  • [COMMAND_EXECUTION]: The skill includes instructions to write execution metadata to a telemetry file (skill-telemetry.md) in a hidden directory (~/.claude/projects/). This is used for internal skill improvement tracking and does not execute arbitrary shell commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — legal-discovery