clause-recon
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill is designed to process sensitive legal contracts and has access to network-enabled tools such as WebFetch. However, tool usage is constrained to the primary purpose of fetching regulatory guidance, and no logic for unauthorized data transmission was identified.
- [PROMPT_INJECTION]: The skill processes untrusted data from both external web sources and local project documents, creating a surface for indirect prompt injection.
- Ingestion points: Project contracts and regulatory websites (SKILL.md, Step 1).
- Boundary markers: None specified to differentiate data from instructions.
- Capability inventory: Access to Bash, Write, and WebFetch tools.
- Sanitization: No explicit validation or sanitization of ingested content is defined.
Audit Metadata