solo-legal

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill analyzes untrusted data from the user's project files, creating a surface for indirect prompt injection.\n
  • Ingestion points: docs/prd.md, CLAUDE.md, and stack configuration files in templates/stacks/ are read to extract feature and stack information.\n
  • Boundary markers: Absent; the instructions do not specify the use of delimiters or warnings to the agent to ignore instructions embedded within the ingested files.\n
  • Capability inventory: The skill's capabilities are limited to local file system operations using Read, Grep, Glob, and Write to create markdown files in a legal/ directory.\n
  • Sanitization: Absent; there is no evidence of content validation or escaping of the data read from the project files before it is processed by the agent.\n- [NO_CODE]: The skill is composed entirely of markdown instructions and configuration and does not include any accompanying executable scripts or binaries.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 09:51 AM