legal-issue-research
Pass
Audited by Gen Agent Trust Hub on Mar 12, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill utilizes strong imperative language and strict workflow constraints (e.g., 'MUST execute', 'MANDATORY'). These are used to ensure the agent maintains a professional legal persona and follows a logical reasoning path, rather than attempting to bypass safety filters or extract system prompts.
- [DATA_EXPOSURE]: To provide accurate legal research, the skill prompts users for specific case details including participant identities, event timelines, and locations. This data collection is functional for legal analysis, and the skill does not attempt to send this information to unauthorized external servers.
- [EXTERNAL_DOWNLOADS]: The skill references several well-known and official Chinese legal databases (e.g., pkulaw.cn, court.gov.cn, gov.cn) as authoritative sources. These are recognized as safe and trusted technology/government services.
- [NO_CODE]: This is a 'no-code' skill that relies entirely on complex prompt engineering and structured templates. It does not distribute or execute scripts, binaries, or shell commands, significantly reducing the attack surface.
- [SAFE]: The skill processes user-provided legal facts into generated reports. While this creates a surface for potential indirect prompt injection, the lack of dangerous capabilities (like code execution or network requests using that data) and the rigid output structure maintain a safe environment.
Audit Metadata