invention-intake

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and analyze untrusted data provided by users in the form of invention disclosures. This represents a potential surface for indirect prompt injection, where malicious instructions could be embedded within the disclosure text to influence agent actions during the generation or storage of memos. The structured nature of the workflow provides some protection, though explicit sanitization is not mentioned.
  • Ingestion points: User-supplied or uploaded invention disclosures in the intake phase (Step 1).
  • Boundary markers: The skill does not define specific delimiters or clear instructions to isolate user-supplied content from system instructions.
  • Capability inventory: The skill utilizes file-writing capabilities to record memos in designated workspaces (~/.claude/plugins/config/claude-for-legal/ip-legal/matters/).
  • Sanitization: There are no explicit instructions for sanitizing or filtering the content provided by users before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:11 AM
Security Audit — agent-trust-hub — invention-intake