alterlab-rma-literature-reviewer

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's persona, capabilities, and workflows are consistent with legitimate academic research tasks. There is no evidence of malicious command execution, obfuscation, or unauthorized data exfiltration.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is designed to ingest and process data from external sources. 1. Ingestion points: The agent reads information from web search results (e.g., academic databases) and local project files. 2. Boundary markers: The prompt lacks explicit delimiters to separate external content from its internal instructions. 3. Capability inventory: The skill utilizes tools for web searching and file system read/write operations. 4. Sanitization: No validation or sanitization logic is specified for data retrieved from external sources before it is analyzed or synthesized.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:45 PM
Security Audit — agent-trust-hub — alterlab-rma-literature-reviewer