alterlab-rma-literature-reviewer
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill's persona, capabilities, and workflows are consistent with legitimate academic research tasks. There is no evidence of malicious command execution, obfuscation, or unauthorized data exfiltration.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface as it is designed to ingest and process data from external sources. 1. Ingestion points: The agent reads information from web search results (e.g., academic databases) and local project files. 2. Boundary markers: The prompt lacks explicit delimiters to separate external content from its internal instructions. 3. Capability inventory: The skill utilizes tools for web searching and file system read/write operations. 4. Sanitization: No validation or sanitization logic is specified for data retrieved from external sources before it is analyzed or synthesized.
Audit Metadata