requete-cph-licenciement-faute-grave-selim-brihi
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXPOSURE]: The skill is designed to collect extensive Personally Identifiable Information (PII), including names, addresses, SIRET numbers, and salary details. This data collection is consistent with its stated purpose of drafting legal claims for the Conseil de prud'hommes.
- [COMMAND_EXECUTION]: The workflow instructions in
references/conseils-variations.mddirect the agent to create a.docxfile and move it between filesystem paths (/home/claudeto/mnt/user-data/outputs). This is a functional requirement for generating the legal document. - [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it ingests untrusted user narratives to populate a structured legal template.
- Ingestion points: User-provided facts and context via interactive dialogue (documented in
SKILL.mdandreferences/conseils-variations.md). - Boundary markers: None identified; user input is directly interpolated into the drafting workflow.
- Capability inventory: The agent is authorized to generate and save
.docxfiles to the output directory. - Sanitization: No explicit sanitization or validation of the user-provided legal arguments is defined in the instructions.
Audit Metadata