custom-nda-generator

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input to influence file content and naming, which presents a surface for potential injection attacks.
  • Ingestion points: User-provided <description> via the /legal nda command in SKILL.md.
  • Boundary markers: Absent. The skill instructions do not specify any delimiters or safety boundaries for the input text.
  • Capability inventory: The skill generates and writes markdown files to the local file system using names derived from user input.
  • Sanitization: Absent. The skill does not define validation or sanitization rules for extracted party names before they are used to generate the output filename, which could potentially be manipulated for path traversal if the underlying agent tool lacks built-in protections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:04 PM
Security Audit — agent-trust-hub — custom-nda-generator