claim-source-verification

Pass

Audited by Gen Agent Trust Hub on Aug 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of instructional Markdown files that define workflows and decision-making taxonomies for scientific verification. There are no executable scripts, binaries, or active code components.
  • [PROMPT_INJECTION]: The use of adversarial terminology (e.g., 'skeptic', 'refute', 'adversarially reviewed') is contextually appropriate for its stated purpose of scientific fact-checking. It does not attempt to bypass system safety filters or override agent constraints.
  • [REMOTE_CODE_EXECUTION]: No package managers (npm, pip, etc.) or remote code download patterns (curl|bash) were detected. The skill operates purely at the instruction and metadata level.
  • [DATA_EXFILTRATION]: The instructions focus on validating publicly available publisher records and publisher previews. No patterns for accessing sensitive local files (~/.ssh, ~/.aws) or exfiltrating data to external servers were found.
  • [DATA_EXPOSURE]: The protocol mandates structured output (JSON) and verbatim quoting of sources, which serves as a security boundary against potential indirect injection from untrusted external sources (e.g., malicious abstracts).
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 11, 2026, 02:50 AM
Security Audit — agent-trust-hub — claim-source-verification