section-writing-agent

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local Python scripts (extract_metrics.py, orphan_cite_gate.py, latex_sanity.py) to process data and validate LaTeX output. These scripts perform deterministic parsing and structural checks on the generated manuscript.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple sources including experimental_log.md, idea.md, and outline.json to generate the paper content.
  • Ingestion points: The agent reads content from workspace/inputs/experimental_log.md, workspace/inputs/idea.md, and workspace/outline.json and interpolates them into a multimodal LLM prompt.
  • Boundary markers: The skill employs a structured system prompt (references/prompt.md) and prepends an anti-leakage prompt to constrain the agent's behavior and minimize data exposure.
  • Capability inventory: The skill possesses the capability to write to the local filesystem (workspace/drafts/paper.tex) and execute local Python validation scripts.
  • Sanitization: The skill implements post-generation validation using latex_sanity.py (checking for unmatched braces and structural errors) and anti_leakage_check.py (detecting PII or affiliation leaks) to mitigate risks associated with the generated content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 01:43 AM
Security Audit — agent-trust-hub — section-writing-agent