deep-risk-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, creating a surface for indirect prompt injection.\n- Ingestion points: The skill uses the
Readtool to access local files and theWebFetchtool to retrieve content from external URLs provided in the/legal risks <file>command.\n- Boundary markers: No specific delimiters or instructions are provided to the agent to treat the ingested contract text as untrusted data or to ignore potential instructions embedded within the text.\n- Capability inventory: The agent has the ability to read files, fetch web content, and write analysis results to a new markdown file (RISK-ANALYSIS.md).\n- Sanitization: The skill lacks sanitization or validation of the input text to filter out potential prompt injection payloads.\n- [DATA_EXFILTRATION]: The skill allows the agent to read any file path provided by the user. If an attacker tricks a user into providing a sensitive system file path (e.g.,.envor SSH keys), the agent may attempt to analyze and quote the sensitive content into the generatedRISK-ANALYSIS.mdfile, leading to unauthorized data exposure.
Audit Metadata