literature-mentor
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external academic sources, creating a surface for indirect prompt injection.
- Ingestion points: As described in
SKILL.md, the agent retrieves full-text content usingzotero_get_item_fulltextandweb_fetchfrom various external sources including Zotero libraries and academic web domains. - Boundary markers: Absent. The instructions do not mandate the use of delimiters (e.g., XML tags or triple quotes) or specific 'ignore embedded instructions' warnings when interpolating retrieved text into the prompt context.
- Capability inventory: The skill has access to Zotero management tools (
zotero_search_items,zotero_get_item_fulltext) and network search capabilities (web_search,web_fetch) as outlined inSKILL.md. - Sanitization: Absent. There is no evidence of instructions to validate, filter, or escape the content retrieved from external sources before the agent processes it.
Audit Metadata