Back to skill

Security audit

Legal Doc Generator

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent legal-document drafting skill, with expected but privacy-sensitive personal-data templates and a disclosed paid activation marker.

Install only if you are comfortable using a paid third-party activation flow. When drafting, use placeholders or masked ID/account numbers until you are ready to submit, verify legal citations independently for important matters, and avoid sending full identity documents, bank details, or evidence bundles through informal chat unless necessary.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (4)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs collecting highly sensitive personal data such as身份证号, home address, phone number, and dispute details, but provides no minimization, consent, retention, redaction, or secure-handling guidance. In a legal-document context this is especially risky because users may disclose enough information for identity theft, doxxing, account recovery abuse, or exposure of employment, housing, and consumer dispute history.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The template instructs users to include身份证号、bank account details, address, and other sensitive identifiers directly in a legal notice, but provides no minimization, redaction, or privacy-handling guidance. If users follow it literally and send the document through insecure or unnecessary channels, they may expose identity and financial data to landlords, intermediaries, or third parties beyond what is legally necessary.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The document recommends WeChat/SMS for sending legal notices and preserving records, but does not warn that these channels may expose personal information, evidence, and legal dispute details to platform retention, account compromise, or unintended recipients. In the context of landlord-tenant disputes, messages may contain identity documents, addresses, photos, and financial evidence, increasing privacy and evidentiary risk.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The templates instruct users to include highly sensitive personal and financial data such as national ID numbers, bank account names, account numbers, and contact details, but provide no warning about privacy exposure, redaction, or minimum necessary disclosure. If users copy these templates into platform complaints, emails, or messages to untrusted merchants, the information could be over-collected, leaked, or abused for identity theft, fraud, or secondary harassment.

Static analysis

No suspicious patterns detected.