hypothesis-generation

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill's instructions and structure are entirely aligned with scientific research best practices. There are no attempts to bypass safety filters, escalate privileges, or hide malicious intent.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use the Bash tool to execute a local Python script (scripts/generate_schematic.py) and standard LaTeX compilation commands (xelatex, bibtex). These operations are necessary for generating diagrams and formatting the final scientific report.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes WebFetch and WebSearch to query scientific repositories such as PubMed. These external interactions are limited to retrieving research literature from well-known and trusted scientific domains.
  • [PROMPT_INJECTION]: The skill processes external data from observations and literature (Ingestion points: SKILL.md). While explicit boundary markers and sanitization are absent, the risk of indirect prompt injection is mitigated by the skill's framework, which requires the agent to critically evaluate data against quality criteria and synthesize it into a structured LaTeX template. Capability inventory includes Bash, Write, and Edit tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 11:30 PM
Security Audit — agent-trust-hub — hypothesis-generation