audit-legal
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project files and external web content to perform audits. This presents a surface for indirect prompt injection where malicious instructions inside reviewed documents could attempt to influence the agent.
- Ingestion points: Processes local files via
ReadandGrepand external content viaWebFetchandWebSearchin Step 1. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore commands found within the audited content.
- Capability inventory: The skill has access to
Bash,Write, andWebFetchtools. - Sanitization: No sanitization or validation of the ingested content is described in the workflow.
Audit Metadata