paper-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from various external sources, including research papers, GitHub repositories, and web search results, which could contain malicious instructions.
- Ingestion points: As described in
SKILL.mdand the specialized prompt files (e.g.,prompts/benchmark.md), the agent retrieves data from user-provided URLs/PDFs and proactively searches for related GitHub repositories, Hugging Face datasets, and author profiles. - Boundary markers: There are no explicit instructions or delimiters defined in the prompt files to help the agent distinguish between informational content and potential instructions hidden within the research papers or metadata.
- Capability inventory: The agent possesses the capability to perform web searches, read external files, and synthesize technical reports based on these external inputs.
- Sanitization: The instructions do not specify any validation, filtering, or escaping of the retrieved external content before it is processed by the agent's logic.
Audit Metadata