clause-playbook

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access commands were detected in the skill instructions. The skill performs its stated purpose of contract analysis.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external websites and local files, creating a potential surface for indirect prompt injection, although this is required for its primary functionality.
  • Ingestion points: Project documents via the Read tool and external websites via WebFetch/WebSearch.
  • Boundary markers: The instructions do not specify the use of delimiters or boundary markers for ingested data.
  • Capability inventory: The skill is configured with tools including Bash and Write, which are standard for the platform but represent a high-capability environment.
  • Sanitization: No explicit content sanitization or validation of retrieved data is described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:48 PM
Security Audit — agent-trust-hub — clause-playbook