Back to skill

Security audit

contract-review-revise

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed contract review and revision skill with expected legal-document handling, but users should confirm jurisdiction and attorney review before relying on its output.

Before installing, understand that this skill may read confidential contracts and create revised Word documents. Confirm the contract language, governing jurisdiction, client role, and desired review mode before use, and have a qualified attorney review any recommendations or edited contract before relying on them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The documentation states 'Primary support: Chinese contracts' and anchors the legal basis to PRC laws, but it does not explicitly ask the user to opt into that locale/legal framework. This can create a language/locale policy issue because users may be steered toward a specific jurisdictional context without clear choice.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.