section-writing-agent
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes local Python scripts (
extract_metrics.py,orphan_cite_gate.py,latex_sanity.py) to process data and validate LaTeX output. These scripts perform deterministic parsing and structural checks on the generated manuscript. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources including
experimental_log.md,idea.md, andoutline.jsonto generate the paper content. - Ingestion points: The agent reads content from
workspace/inputs/experimental_log.md,workspace/inputs/idea.md, andworkspace/outline.jsonand interpolates them into a multimodal LLM prompt. - Boundary markers: The skill employs a structured system prompt (
references/prompt.md) and prepends an anti-leakage prompt to constrain the agent's behavior and minimize data exposure. - Capability inventory: The skill possesses the capability to write to the local filesystem (
workspace/drafts/paper.tex) and execute local Python validation scripts. - Sanitization: The skill implements post-generation validation using
latex_sanity.py(checking for unmatched braces and structural errors) andanti_leakage_check.py(detecting PII or affiliation leaks) to mitigate risks associated with the generated content.
Audit Metadata