literature-mentor

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external academic sources, creating a surface for indirect prompt injection.
  • Ingestion points: As described in SKILL.md, the agent retrieves full-text content using zotero_get_item_fulltext and web_fetch from various external sources including Zotero libraries and academic web domains.
  • Boundary markers: Absent. The instructions do not mandate the use of delimiters (e.g., XML tags or triple quotes) or specific 'ignore embedded instructions' warnings when interpolating retrieved text into the prompt context.
  • Capability inventory: The skill has access to Zotero management tools (zotero_search_items, zotero_get_item_fulltext) and network search capabilities (web_search, web_fetch) as outlined in SKILL.md.
  • Sanitization: Absent. There is no evidence of instructions to validate, filter, or escape the content retrieved from external sources before the agent processes it.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 10:08 AM