aer-referee-sim

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided manuscripts which could theoretically contain instructions intended to influence the agent. However, the skill implements a strict adversarial persona and a formal scoring rubric that serve as strong boundary constraints.
  • Ingestion points: Processes the 'complete draft' (body, exhibits, bibliography) provided by the user.
  • Boundary markers: None explicitly defined in the prompt interpolation, but the output is strictly gated by a specific rubric.
  • Capability inventory: None; the skill generates text-based reports and does not execute shell commands or network requests.
  • Sanitization: None specified for input text.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 09:21 AM
Security Audit — agent-trust-hub — aer-referee-sim