literature-extensive-read

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a file 'literature-extensive-read_audit_result_v1.json' that contains numerous 'security: PASS' assertions and audit scores. This is a self-referential pattern (Category 8e) where the skill attempts to define its own safety status to influence automated security analysis.
  • [PROMPT_INJECTION]: The skill ingests untrusted content from academic papers (paper.md) without providing the agent with boundary markers or instructions to disregard embedded malicious prompts. Ingestion points: instructions to read 'paper.md' in 'SKILL.md'. Boundary markers: None. Capability inventory: The skill is limited to local file system operations (read input/write summary); no network or remote code execution capabilities are authorized. Sanitization: Absent.
  • [EXTERNAL_DOWNLOADS]: 'SKILL.md' identifies 'pdf-extract' and 'securityclaw' as external CLI dependencies required for the paper conversion and auditing workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 08:22 AM
Security Audit — agent-trust-hub — literature-extensive-read