paper-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data in the form of manuscript drafts, sections, and reviewer comments.
- Ingestion points: The skill ingests user-provided text across various classes identified in
SKILL.md, such asmanuscript,passage,results-flow, andresponse. - Boundary markers: The instructions lack explicit delimiters or 'ignore embedded instructions' warnings for the data being processed.
- Capability inventory: The workflow coordinates multiple high-capability skills that perform file modifications, structural optimization, and integrity audits.
- Sanitization: There is no evidence of sanitization, escaping, or validation to distinguish between manuscript content and potential instructions embedded by an attacker within the text.
Audit Metadata