lay-summary-for-cross-disciplinary-teams
Warn
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: MEDIUMMETADATA_POISONINGINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill includes an auxiliary JSON file (eval_report_Lay-Summary-for-Cross-Disciplinary-Teams_result.json) that contains self-referential security verdicts and safety claims, such as 'security': 'PASS'. This metadata pattern is deceptive as it attempts to provide pre-baked conclusions to influence security assessments.
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing external research data, which presents a surface for indirect prompt injection attacks. 1. Ingestion points: Technical research material including abstracts, results sections, and internal reports (defined in Step 1 of SKILL.md). 2. Boundary markers: Instructions do not specify delimiters or 'ignore instructions' warnings to distinguish between research data and potential embedded instructions. 3. Capability inventory: No dangerous capabilities are present; the skill does not use external tools, perform network operations (beyond static documentation links), or modify the file system. 4. Sanitization: No validation or sanitization logic is implemented for the ingested research content.
Audit Metadata