experiment-story-writer
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill logic is transparent and focused on academic document generation. No malicious patterns such as prompt injection, obfuscation, or unauthorized data exfiltration were detected.
- [INDIRECT_PROMPT_INJECTION]: The skill includes ingestion points for untrusted data, specifically experiment logs and reports found in directories like
docs/results/anddocs/runs/. While this represents an attack surface for indirect prompt injection, it is essential to the skill's primary function of evidence synthesis. The skill lacks instructions that would cause the agent to execute code found within these data sources, and there are no network exfiltration patterns combined with this ingestion.
Audit Metadata