citation-guard

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate citation verification by comparing generated references against a local research corpus. It operates within the local file system and does not request network access or execute arbitrary system commands.
  • [SAFE]: The skill ingests content from research documents, which represents an indirect prompt injection surface; however, this is inherent to its primary function and is considered safe due to the absence of dangerous capabilities such as network exfiltration or arbitrary command execution.
  • Ingestion points: Research files located in .aiwg/research/sources/ and .aiwg/research/findings/ (SKILL.md).
  • Boundary markers: None identified.
  • Capability inventory: Local file system read access, file write to .aiwg/research/TODO.md (SKILL.md), and influence over agent output messages.
  • Sanitization: No input sanitization or filtering of research content is performed prior to processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 01:04 AM
Security Audit — agent-trust-hub — citation-guard