region-adjudicator

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill architecture is susceptible to indirect prompt injection because it instructs the agent to ingest and evaluate content from external legal databases and third-party lawyer articles.
  • Ingestion points: External data is fetched via tools referencing [YD] 法律精灵, [GOV] 裁判文书网, and [WKL] 律师分析 as specified in SKILL.md.
  • Boundary markers: There are no explicit instructions or delimiters provided to prevent the agent from executing instructions potentially embedded in the fetched legal documents or articles.
  • Capability inventory: The skill is purely informational and lacks any identified capabilities for shell execution, file system modification, or network-based exfiltration.
  • Sanitization: No sanitization or validation protocols are established for the external data before it is processed by the agent.
  • [SAFE]: The skill contains no obfuscated code, hardcoded credentials, or unauthorized persistence mechanisms. Accessing context from ../CLAUDE.md is a standard pattern for shared configurations in this environment and does not pose a security risk in this context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 04:17 PM
Security Audit — agent-trust-hub — region-adjudicator