skill-injection-defense

Audit legal AI skills and workflows for prompt injection and data leakage.

630|79|Updated Dec 18, 2025
One-click install
npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill skill-injection-defense
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: skill-injection-defense
Source: https://github.com/lawve-ai/awesome-legal-skills/tree/main/skills/skill-injection-defense-ignacio-adrian-lerer
Command: npx skills add https://github.com/lawve-ai/awesome-legal-skills --skill skill-injection-defense

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Audits and validates legal AI skills, prompts, workflows, and supply-chain artifacts to prevent prompt injection, data leakage, and unsafe behavior before installation or deployment.

Core Features & Use Cases

  • Threat detection: identifies prompt injection, hidden instructions, and unsafe configurations in SKILL.md, prompts, and scripts.
  • Supply-chain hygiene: reviews manifests, references, and tool definitions to prevent credential exposure and exfiltration risks.
  • Use Case: If you are evaluating a new skill, this review ensures zero leakage of client data and adherence to legal and ethical standards.

Quick Start

Review the provided skill and generate a risk verdict with actionable recommendations.

Frequently Asked Questions about skill-injection-defense

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I audit legal AI skills for prompt injection and data leakage?

To audit legal AI skills for prompt injection and data leakage, review the SKILL.md, prompts, and scripts to identify hidden instructions and unsafe configurations. This process validates metadata completeness, threat coverage, and supply-chain hygiene before deployment.

What is prompt injection risk assessment for third-party AI agents?

Prompt injection risk assessment for third-party AI agents is the process of evaluating marketplace prompts and workflows to detect hidden instructions, credential exposure, and data exfiltration risks. It ensures client data remains secure and prevents unauthorized behavior.

How do I check AI supply-chain artifacts for unsafe configurations?

Check AI supply-chain artifacts by reviewing manifests, references, and tool definitions to prevent credential exposure and exfiltration risks. This supply-chain hygiene step validates operational instructions and asset references before installing new skills.

When do I need to vet legal AI prompts before deployment?

You need to vet legal AI prompts before deployment whenever evaluating new third-party skill submissions or integrating agent workflows into procurement and development. This ensures zero leakage of client data and adherence to legal and ethical standards.

Does legal AI security review work with SKILL.md and frontmatter metadata?

Yes, legal AI security review works with SKILL.md and frontmatter metadata by evaluating these files to identify threat coverage and risk signaling. It validates metadata completeness and operational instructions to harden the skill for safety.