research-grants

Warn

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user or agent to download a LaTeX template from a personal GitHub repository ('https://github.com/L-TChen/nstc-proposal.git') in the 'references/nstc_guidelines.md' file. This source is not associated with a trusted organization or a well-known service provider.
  • [REMOTE_CODE_EXECUTION]: The documentation in 'references/nstc_guidelines.md' directs the installation of the 'nstc-proposal' package using 'tlmgr install', which fetches and installs code from the Comprehensive TeX Archive Network (CTAN). While CTAN is a standard repository for the TeX community, installing third-party packages at runtime can introduce risks if the packages are unverified.
  • [COMMAND_EXECUTION]: The 'SKILL.md' file contains a 'MANDATORY' instruction for the agent to execute 'python scripts/generate_schematic.py'. However, the 'scripts/' directory and the 'generate_schematic.py' file are not provided within the skill's file list. Similar references to missing scripts such as 'compliance_checker.py', 'budget_calculator.py', and 'deadline_tracker.py' are found in 'SKILL.md', creating a risk where the agent might attempt to generate or fetch missing executable content to satisfy these instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 6, 2026, 11:31 PM
Security Audit — agent-trust-hub — research-grants