Skills
Skill Injection Defense
A practice-area skill: it carries legal knowledge — a doctrine, a regime, a review standard — and applies it to your material.
What this skill does
Audits legal AI skills, prompts, workflows, MCP/tool instructions, and agent packages before they are trusted or installed. It detects prompt injection, hidden or hostile instructions, unsafe scripts, suspicious frontmatter, credential exposure, exfiltration paths, persistence mechanisms, cron/launchd hooks, unauthorized network calls, and supply-chain risk. Use it before adopting third-party or generated skills; before publishing a skill to a legal AI marketplace; when reviewing SKILL.md files, skill folders, scripts, references, MCP manifests, or automation instructions; or when a user asks whether an AI workflow is safe. Paste or upload the skill, prompt, MCP/tool instruction, etc you want to review. The auditor treats the material as untrusted data: it does not execute scripts, install packages, or obey commands embedded inside the reviewed content. It returns a verdict — approve, approve with constraints, rewrite, quarantine, or reject — plus the key risks and recommended remediation.
- Injection
- Defense
Free, and published by its author - not by HAQQ. The link leaves this site.
Where it runs, and how to install it
Agent Skills are a format, not a product feature: a folder with a SKILL.md and whatever files it needs. Nothing inside one is model-specific.
- Claude
- Drop the skill folder into ~/.claude/skills/, or upload it in Settings → Capabilities. Claude loads it when the description matches what you asked for.
- Claude Code
- Same folder, per-project instead: .claude/skills/ inside the repository, so the skill travels with the work rather than with the machine.
- Any agent that reads SKILL.md
- A skill is a folder with a SKILL.md and whatever files it needs. Nothing in the format is model-specific, so a runtime that reads the file reads the skill.
More from Ignacio Adrián Lerer
- Agentic Delegation AuditUse when a lawyer, legal team, or client needs to assess AI agents that can act on someone's behalf: send messages, search, draft, file, pay, delete, connect to accounts, use tools, or rely on external data. Produces a practical delegation, oversight, accountability, and control audit for legal operations.
- Decision Ownership AuditAudits AI-assisted legal, compliance, governance, and institutional decisions before reliance to determine whether the responsible human or institution has enough access to the evidence, reasoning basis, uncertainty, authority, and review path to genuinely own the decision rather than merely approve, sign, or transmit it.
- Due Diligence GateUse for due diligence, legal-financial risk review, investment or business transaction checklists, and preliminary screening where facts, documents, assumptions, legal uncertainty, debt/equity, assets/liabilities, contracts, tax, regulatory, compliance, technology/product, and financial-model issues must be separated clearly.
- Epistemic Fault Line AuditAudits legal AI outputs, prompts, skills, workflows and MCP/tool instructions for fluent but unsupported reasoning, missing evidence, overconfidence, hidden assumptions, weak causal links and absent human-review gates.
- Financial Comparison GlossaryUse when a calculator, financial model, investor memo, due diligence report, risk review, dashboard, or client-facing explanation needs clear distinctions between accounting and finance concepts such as cash flow vs profit, EBIT vs EBITDA, CapEx vs OpEx, debt vs equity, market value vs book value, ROI vs ROE, assets vs liabilities, and accounting vs finance.
- Argentine Supreme Court AnalysisPageRank-based jurisprudential authority analysis for Argentine case law (CSJN, federal courts). Peer-reviewed methodology published in JCLLT (DOI: 10.47852/bonviewJCLLT62027951). Ranks precedents by citation network influence with temporal decay.
Skills that do related work
- Agent Authority Charter BuilderCreates an Agent Authority Charter for enterprise or regulated AI agents before deployment. Use this Skill when a user needs to define what an AI agent is allow
- Agentic Delegation AuditUse when a lawyer, legal team, or client needs to assess AI agents that can act on someone's behalf: send messages, search, draft, file, pay, delete, connect to
- AI Audit TrailThis skill builds a structured audit trail of an AI-assisted task: what the tool was asked to do, what materials it was given, what it produced, how the output
- AI Governance ReviewerConduct AI governance, legal-risk, privacy, compliance, procurement, or vendor-risk reviews of internal AI use cases, AI product features, LLM workflows, or thi
- Ai InventoryEU AI Act per-system inventory — track each AI system's role (provider, deployer, importer, distributor, authorized representative, product manufacturer) and ri
- Aia GenerationRun an AI impact assessment — structured intake, risk analysis, regulatory classification per regime in scope, policy consistency diff, and recommendation with