contract-review

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process untrusted contract data, which presents a surface for indirect prompt injection attacks.
  • Ingestion points: Contract text supplied by the user during the review process (SKILL.md).
  • Boundary markers: The prompt does not specify delimiters or guidelines to ignore instructions embedded within the contract text.
  • Capability inventory: The agent's capabilities are limited to textual report generation and does not include execution of shell commands, file system writes, or network requests.
  • Sanitization: No explicit sanitization or filtering of the input text is provided in the instructions.
  • [EXTERNAL_DOWNLOADS]: The skill includes a reference to an external skill repository (github:mindverse/skillhub) to provide users with additional capabilities. This reference targets a well-known service and is intended for user-initiated tool discovery.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 03:44 PM