alterlab-research-grants

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The reference guide for Taiwan's NSTC grants (references/nstc_guidelines.md) provides instructions for cloning LaTeX templates from GitHub repositories (e.g., L-TChen/nstc-proposal) and installing packages using the TeX Live Manager (tlmgr). These resources are hosted on well-known public repositories and package registries intended for academic document preparation.
  • [COMMAND_EXECUTION]: The main skill instructions (SKILL.md) direct the agent to execute local Python scripts, such as scripts/generate_schematic.py, scripts/compliance_checker.py, and scripts/budget_calculator.py. These scripts are intended to automate visual schematic generation and compliance auditing. Although the execution commands are explicitly provided, the source files for these scripts were not included in the provided skill package.
  • [DATA_EXFILTRATION]: Not detected. The skill contains numerous URLs pointing to official government portals (e.g., nsf.gov, grants.nih.gov, science.osti.gov, darpa.mil) and institutional research services, which are standard for the grant application process.
  • [PROMPT_INJECTION]: Not detected. The instructions maintain a professional, academic focus and do not contain patterns aimed at bypassing AI safety guidelines or overriding system prompts.
  • [INDIRECT_PROMPT_INJECTION]: The skill represents an attack surface for indirect prompt injection as it processes user-supplied research descriptions and diagram requirements which are then passed to shell-based tools (e.g., scripts/generate_schematic.py). However, no malicious exploitation of this surface was observed in the static content.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 12:47 AM
Security Audit — agent-trust-hub — alterlab-research-grants