contract-comparison
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted content from external sources.
- Ingestion points: Untrusted data enters the agent's context through file paths (via the
Readtool) or URLs (via theWebFetchtool) provided as arguments to the/legal comparecommand. - Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" directives to prevent the agent from potentially executing instructions hidden within the contract text.
- Capability inventory: The agent possesses capabilities to read files, perform network fetches, and write files (
CONTRACT-COMPARISON.md), which could be abused if an injection is successful. - Sanitization: There is no evidence of sanitizing, escaping, or validating the input text before it is analyzed and quoted in the final output.
Audit Metadata