aer-robustness
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted research manuscripts and datasets to generate analysis plans and execute statistical tools. \n- Ingestion points: Manuscript drafts and data files read to perform robustness and heterogeneity checks in
SKILL.mdandreferences/robustness-menu.md. \n- Boundary markers: There are no explicit instructions or delimiters (e.g., XML tags or clear warnings) to prevent the agent from following malicious instructions potentially embedded in the manuscripts being analyzed. \n- Capability inventory: The skill utilizes an MCP server (StatsPAI) with capabilities such asaudit_result,spec_curve, andwild_cluster_bootstrapthat perform complex logic based on the processed data. \n- Sanitization: No evidence of sanitization or filtering of the external manuscript content before it influences the agent's planning or tool usage.
Audit Metadata