hypothesis-generation
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious code, obfuscation, unauthorized data exfiltration, or credential harvesting was detected. The skill operates within its stated functional boundaries.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute document processing commands, specifically 'xelatex' and 'bibtex' for report generation, and a Python script ('scripts/generate_schematic.py') for schematic creation. These commands are integral to the skill's primary purpose of producing scientific documents.
- [PROMPT_INJECTION]: The skill retrieves data from external sources like PubMed and general web search. While this involves processing untrusted content that could contain indirect prompt injections, the workflow is transparently part of a research methodology and subject to standard agent safety boundaries.
Audit Metadata