Back to skill

Security audit

Legal Documents

Security checks across malware telemetry and agentic risk

Overview

This is a coherent CellCog legal-drafting skill, but users should treat prompts and documents as potentially sensitive external-service data.

Before installing, confirm you are comfortable using CellCog for legal drafting and avoid sending confidential client material, regulated health data, trade secrets, or real personal details unless you are authorized and understand CellCog’s data handling terms. Have any generated legal document reviewed by a qualified attorney before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill encourages users to submit prompts containing highly sensitive legal, personal, employment, health, and business data to an external API-backed service, but it does not clearly warn that this information will leave the local agent environment. In a legal-document context, users are especially likely to include confidential or regulated data, so the omission can cause unintended disclosure, privacy violations, or contractual confidentiality breaches.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.