paper-sprint-review

Warn

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes a deceptive evaluation report file named eval_report_paper-sprint-review_result.json that makes false claims about its security status. It asserts a 'SAFE' verdict and fabricated evaluation results from a future date to mislead security reviewers and automated scanners.
  • [COMMAND_EXECUTION]: The references/export.md file specifies shell commands that use unvalidated variables for document conversion via pandoc. This pattern allows for potential command injection if parameters like output directories or project IDs are influenced by untrusted input.
  • [PROMPT_INJECTION]: The skill's workflow ingests untrusted manuscripts and possesses powerful capabilities like file writing and shell execution, creating an indirect prompt injection surface. The analysis found no boundary markers or sanitization logic to prevent malicious content in documents from influencing agent behavior. Ingestion: manuscripts provided via /ps intake. Capabilities: shell execution (pandoc), file writing (Write tool). Sanitization: None.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 20, 2026, 01:51 AM
Security Audit — agent-trust-hub — paper-sprint-review