legal-risk-assessment-anthropic
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of markdown instructions and documentation templates without any executable scripts or system commands.
- [SAFE]: No network access, file system modifications, or sensitive data access patterns were detected.
- [NO_CODE]: The skill does not include any scripts (Python, JavaScript, or Shell) or binary executables, which eliminates the possibility of remote code execution or unauthorized system access.
- [PROMPT_INJECTION]: The skill evaluates external data (legal matter descriptions), creating a surface for indirect prompt injection. However, the lack of tool access or system capabilities renders this surface safe from traditional exploitation. The primary risk is limited to potential manipulation of the assessment results.
- Ingestion points: Matter description, background, and context fields in the documentation templates within SKILL.md.
- Boundary markers: Absent.
- Capability inventory: None; the skill does not use any tools or scripts.
- Sanitization: Absent.
Audit Metadata