result-figure-consistencycheck
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user-provided Markdown from
inputs/paper_fulltext.md, creating a surface for indirect prompt injection attacks where malicious instructions could be embedded in the paper text to manipulate output.\n - Ingestion points: The file
inputs/paper_fulltext.mdserves as the primary data input for the agent.\n - Boundary markers: Absent. There are no instructions provided to the agent to help it distinguish between document content and operational commands.\n
- Capability inventory: The skill performs text analysis and writes reports to the
outputs/directory.\n - Sanitization: Absent. The skill does not describe any validation or escaping of the input text.\n- [PROMPT_INJECTION]: The skill includes a self-referential audit file
result-figure-consistencycheck_audit_result_v1.jsonthat makes explicit safety claims and provides security scores.\n - Evidence: The file contains metadata such as "security": "PASS" and an internal security score. These claims are treated as data for evaluation rather than authoritative conclusions.\n- [NO_CODE]: The skill does not contain any executable scripts or binaries, relying entirely on markdown instructions and templates.
Audit Metadata