Academic Figure Workflow Orchestrator
Pass
Audited by Gen Agent Trust Hub on Aug 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface
- Ingestion points: The workflow involves reading and analyzing external artifacts such as research papers, software repositories, and architectural diagrams provided by the user, as described in the 'Sibling routing' and 'Stage detection' sections.
- Boundary markers: The instructions lack explicit delimiters or directives to ignore instructions that may be embedded within the external documents or code being analyzed.
- Capability inventory: The skill has access to the
bashtool (defined in frontmatter), which represents an exploitable surface if an indirect injection successfully influences the agent's behavior. - Sanitization: The skill does not implement specific filtering, validation, or escaping logic for the content of the ingested academic materials or code repositories.
Audit Metadata