limitation-and-risk-writer

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [SAFE]: A detailed analysis of the skill instructions and the accompanying Python script found no patterns related to credential theft, obfuscation, or unauthorized network operations.
  • [EXTERNAL_DOWNLOADS]: The skill includes a reference to the author's official GitHub repository (github.com/aipoch/medical-research-skills) for documentation and source attribution, which is categorized as a legitimate vendor resource.
  • [PROMPT_INJECTION]: The skill processes user-provided research data (SKILL.md, Step 1) which represents a potential indirect prompt injection surface. Evidence chain: (1) Ingestion points: User-provided study limitations in SKILL.md; (2) Boundary markers: Explicit 'Hard Rules' and 'Step 5 Calibration Check' serve as delimiters; (3) Capability inventory: No subprocess calls, network operations, or dynamic code execution found in any scripts (scripts/main.py is a static template generator); (4) Sanitization: The workflow incorporates a mandatory verification checklist to maintain scientific integrity and prevent the fabrication of data.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:51 AM
Security Audit — agent-trust-hub — limitation-and-risk-writer