missing-protections-finder
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external sources, creating a surface for indirect prompt injection attacks.
- Ingestion points: The skill reads local files via the
Readtool, fetches remote content via theWebFetchtool, and processes inline text provided by the user inSKILL.md(Step 1). - Boundary markers: The instructions lack explicit boundary markers or "ignore embedded instructions" warnings when processing the contract text.
- Capability inventory: The agent has the capability to read files, fetch data from URLs, and write new files to the filesystem (
MISSING-PROTECTIONS-[contract-name].mdin Step 5). - Sanitization: There is no mention of sanitization or validation of the input text before the agent identifies contract types or suggests clauses.
- [COMMAND_EXECUTION]: The skill implements the
/legal missing <file>command pattern, which triggers the automated analysis workflow involving file reading and network fetching based on user-provided arguments.
Audit Metadata