academic-research
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documentation encourages the installation of the 'academic-research-skills' suite from an external GitHub repository (Imbad0202/academic-research-skills) and the use of the 'jeo-skills' toolset.
- [DATA_EXFILTRATION]: The skill includes an optional 'Cross-Model Verification' feature (Stage 7) that transmits research data to external AI service providers such as OpenAI, DeepSeek, or other user-specified endpoints for verification purposes.
- [COMMAND_EXECUTION]: The skill relies on the
Bashtool to orchestrate its multi-stage pipeline, including managing local file state (e.g., Material Passport JSON files) and coordinating various agent tasks. - [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves ingesting and processing untrusted data from the web (via WebFetch) and user-provided academic papers, which serves as a potential surface for indirect prompt injection.
- Ingestion points: Research papers fetched from the web in Stage 2 (Literature Sweep) and documents provided by the user for review or revision modes.
- Boundary markers: The instructions do not specify explicit delimiters or isolation protocols for the ingested content.
- Capability inventory: The skill utilizes
Bash,Write,Edit, andWebFetchtools to execute its pipeline stages. - Sanitization: There is no explicit documentation of sanitization or filtering steps for the ingested external research content.
Audit Metadata