triage-nda

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and analyze external NDA text or files provided via the @$1 argument. This creates a potential surface for indirect prompt injection, where text within a document could be crafted to influence the agent's behavior. For example, a document might contain hidden instructions attempting to persuade the agent to ignore specific red flags or to always classify the document as 'GREEN' regardless of its actual content.
  • Ingestion and Boundary Markers: The workflow accepts input in various formats (file upload, URL, or pasted text) and interpolates it directly into the analysis prompt. The absence of explicit boundary markers or instructions to ignore embedded commands within the analyzed text increases the possibility that the agent might inadvertently follow instructions contained inside the NDA instead of strictly analyzing its legal structure.
  • Capability Context: While the skill processes untrusted data, its primary capabilities are limited to text analysis and report generation. It does not appear to possess high-risk capabilities such as arbitrary command execution, network exfiltration, or file system modifications, which significantly limits the potential impact of an injection attempt.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:16 AM
Security Audit — agent-trust-hub — triage-nda