Back to skill

Security audit

corporate-legal

Security checks across malware telemetry and agentic risk

Overview

This legal-workflow skill is coherent overall but needs Review because it can persist sensitive legal documents and reports to Notion without clear consent, redaction, or retention controls.

Install only if your organization permits legal materials to be stored in Notion. Before using the Notion connector, confirm exactly what will be written, redact personal identifiers and privileged facts where possible, and use an approved workspace with appropriate access controls and retention rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (7)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The README states the skill can be triggered through natural conversation and automatically matched, but it does not define clear activation boundaries or disambiguation rules. In a multi-skill environment, this can cause unintended invocation of legal workflows on loosely related user input, increasing the chance of misrouting sensitive corporate or compliance requests.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Several trigger keywords are broad and overlapping, such as terms for risk, compliance, legal documents, and case lookup, which can match ordinary legal discussion rather than a deliberate request to invoke a specific subskill. Because this skill operates in a corporate legal context involving sensitive analysis and document generation, ambiguous routing could lead to the wrong subskill processing privileged or regulated information.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The skill advertises many broad trigger phrases such as general legal help, due diligence, risk assessment, and document drafting. Because these overlap with common user requests, the skill can be invoked unintentionally and then steer the assistant into rigid template execution, potentially causing inappropriate handling of sensitive legal, compliance, or signing workflows without clear user intent.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly suggests writing signing configurations, status tracking, and post-signing records to Notion, but provides no warning or control guidance for handling sensitive contract data, signer identities, emails, approval metadata, or legal records. In a corporate legal e-signature workflow, this omission can lead users to copy regulated or confidential information into a third-party knowledge base without considering minimization, access control, retention, or cross-border processing risks.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly supports writing legal daily/weekly reports to Notion, which may contain sensitive legal matters, contract status, litigation updates, compliance issues, deadlines, and internal requests, but it provides no privacy warning, data-minimization guidance, or user confirmation before sending that information to an external service. In a corporate legal context, this increases the risk of unauthorized disclosure, cross-border data handling issues, and compliance violations if users unknowingly sync privileged or confidential content to Notion.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports sending generated legal documents to Notion for collaboration, but the surrounding instructions also require highly sensitive inputs such as personal identifiers, company information, dispute facts, evidence, and legal strategy. Without a clear warning, consent step, data-minimization guidance, or redaction controls before connector use, users may unknowingly transmit sensitive legal and personal data to an external third-party service, creating confidentiality, privacy, and regulatory exposure.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly promotes writing legal risk assessments and risk registers to Notion, which can contain highly sensitive corporate, contractual, compliance, and dispute-related information, but it does not warn users that this data may be transmitted to a third-party service. In a corporate legal context, that omission increases the chance of unauthorized disclosure, over-sharing, and regulatory or confidentiality issues, especially where personal data, trade secrets, or privileged legal analysis may be included.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.