aer-workflow
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The 'Skill Optimization Loop' section in SKILL.md contains instructions for the user or agent to execute local maintenance scripts (python3 scripts/run_skillopt_gate.py) and build commands (make preflight) during development and testing of the skill.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as manuscript drafts and reviewer reports. Ingestion points: Raw manuscript text and referee reports are loaded into the agent's context during the writing and review stages. Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions for the processed content. Capability inventory: The workflow includes an optional aer-statspai engine, which is an MCP server capable of executing Python code for statistical analysis. Sanitization: No evidence of sanitization for the external manuscript content was found.
Audit Metadata