deep-risk-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 30, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, creating a surface for indirect prompt injection.\n- Ingestion points: The skill uses the Read tool to access local files and the WebFetch tool to retrieve content from external URLs provided in the /legal risks <file> command.\n- Boundary markers: No specific delimiters or instructions are provided to the agent to treat the ingested contract text as untrusted data or to ignore potential instructions embedded within the text.\n- Capability inventory: The agent has the ability to read files, fetch web content, and write analysis results to a new markdown file (RISK-ANALYSIS.md).\n- Sanitization: The skill lacks sanitization or validation of the input text to filter out potential prompt injection payloads.\n- [DATA_EXFILTRATION]: The skill allows the agent to read any file path provided by the user. If an attacker tricks a user into providing a sensitive system file path (e.g., .env or SSH keys), the agent may attempt to analyze and quote the sensitive content into the generated RISK-ANALYSIS.md file, leading to unauthorized data exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 30, 2026, 07:04 PM
Security Audit — agent-trust-hub — deep-risk-analysis