aer-robustness

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing untrusted research manuscripts and datasets to generate analysis plans and execute statistical tools. \n- Ingestion points: Manuscript drafts and data files read to perform robustness and heterogeneity checks in SKILL.md and references/robustness-menu.md. \n- Boundary markers: There are no explicit instructions or delimiters (e.g., XML tags or clear warnings) to prevent the agent from following malicious instructions potentially embedded in the manuscripts being analyzed. \n- Capability inventory: The skill utilizes an MCP server (StatsPAI) with capabilities such as audit_result, spec_curve, and wild_cluster_bootstrap that perform complex logic based on the processed data. \n- Sanitization: No evidence of sanitization or filtering of the external manuscript content before it influences the agent's planning or tool usage.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 09:21 AM
Security Audit — agent-trust-hub — aer-robustness