requete-cph-licenciement-faute-grave-selim-brihi

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill is designed to collect extensive Personally Identifiable Information (PII), including names, addresses, SIRET numbers, and salary details. This data collection is consistent with its stated purpose of drafting legal claims for the Conseil de prud'hommes.
  • [COMMAND_EXECUTION]: The workflow instructions in references/conseils-variations.md direct the agent to create a .docx file and move it between filesystem paths (/home/claude to /mnt/user-data/outputs). This is a functional requirement for generating the legal document.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted user narratives to populate a structured legal template.
  • Ingestion points: User-provided facts and context via interactive dialogue (documented in SKILL.md and references/conseils-variations.md).
  • Boundary markers: None identified; user input is directly interpolated into the drafting workflow.
  • Capability inventory: The agent is authorized to generate and save .docx files to the output directory.
  • Sanitization: No explicit sanitization or validation of the user-provided legal arguments is defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 10:17 AM