jurisdiction-format

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted text from multiple user-controlled files to generate jurisdiction-specific patent filings, creating an attack surface where embedded instructions could influence the agent's behavior.
  • Ingestion points: Untrusted content is read from patent/CLAIMS.md, patent/specification/ (multiple files), patent/figures/, and patent/INVENTION_DISCLOSURE.md.
  • Boundary markers: The instructions do not specify any delimiters or safety prompts to treat the ingested patent text strictly as data, increasing the risk that the agent may follow instructions embedded within the patent draft.
  • Capability inventory: The skill is configured with broad tool access including Bash(*), Read, Write, Edit, Grep, and Glob, which could be exploited if an indirect injection is successful.
  • Sanitization: No sanitization, filtering, or escaping logic is described for the content being reformatted and written to the patent/output/ directory.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:08 AM
Security Audit — agent-trust-hub — jurisdiction-format