alterlab-paper-writer

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is configured to use the tectonic LaTeX engine for compiling academic papers into PDFs and pandoc for document format conversions (e.g., Markdown to DOCX). These system calls are necessary for the primary purpose of the skill and follow standard academic workflows.
  • [EXTERNAL_DOWNLOADS]: The citation_compliance_agent includes instructions to cross-reference citations against the Retraction Watch Database (retractionwatch.com). This is a well-known service used for verifying the integrity of academic sources and does not involve the transfer of sensitive data.
  • [PROMPT_INJECTION]: The skill includes a revision_coach_agent designed to parse unstructured feedback from reviewers. While this creates a surface for indirect prompt injection, the skill implements a protective layer by parsing this feedback into a structured database (Revision Roadmap) and classifying items (Major/Minor/Editorial) before they are used to influence the paper's content.
  • [SAFE]: The skill is transparently authored and includes numerous quality gates, such as mandatory AI disclosure statements, ethical considerations, and standard citation guides. Analysis of the 44 skill files revealed no signs of obfuscation, hardcoded credentials, or unauthorized persistence mechanisms.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 12:46 AM
Security Audit — agent-trust-hub — alterlab-paper-writer