skills/tonone-ai/tonone/keel-legal/Gen Agent Trust Hub

keel-legal

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as its primary function is to ingest and process untrusted external data in the form of legal contracts and agreements.
  • Ingestion points: The skill processes user-supplied documents for identification and review as described in Step 1 and Step 2 of SKILL.md.
  • Boundary markers: There are no explicit delimiters or boundary instructions provided to separate the external document content from the agent's instructions.
  • Capability inventory: The skill has access to several powerful tools including Bash, Read, Glob, Grep, and WebFetch.
  • Sanitization: The instructions do not specify any sanitization, filtering, or validation of the content contained within the documents being reviewed.
  • [COMMAND_EXECUTION]: The skill's configuration in SKILL.md allows the use of the Bash tool. While no malicious shell commands are present in the provided instructions, the tool provides the capability for local command execution which could be targeted by indirect injection.
  • [EXTERNAL_DOWNLOADS]: The skill includes the WebFetch tool, which allows the agent to retrieve data from external URLs. This is a functional requirement for reviewing web-based terms of service or SaaS agreements but represents a network access capability.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:58 AM
Security Audit — agent-trust-hub — keel-legal