literature-extensive-read
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill includes a file 'literature-extensive-read_audit_result_v1.json' that contains numerous 'security: PASS' assertions and audit scores. This is a self-referential pattern (Category 8e) where the skill attempts to define its own safety status to influence automated security analysis.
- [PROMPT_INJECTION]: The skill ingests untrusted content from academic papers (paper.md) without providing the agent with boundary markers or instructions to disregard embedded malicious prompts. Ingestion points: instructions to read 'paper.md' in 'SKILL.md'. Boundary markers: None. Capability inventory: The skill is limited to local file system operations (read input/write summary); no network or remote code execution capabilities are authorized. Sanitization: Absent.
- [EXTERNAL_DOWNLOADS]: 'SKILL.md' identifies 'pdf-extract' and 'securityclaw' as external CLI dependencies required for the paper conversion and auditing workflow.
Audit Metadata