citation-check

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external files (manuscripts and bibliography files), which represents a surface for indirect prompt injection.
  • Ingestion points: The workflow ingests content from external sources such as LaTeX, Markdown, PDF text, .bib files, and CSL JSON (defined in Step 1 and 2 of the instructions).
  • Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded within the processed text.
  • Capability inventory: The skill itself does not define any executable tools, shell commands, or network exfiltration capabilities. It is limited to textual analysis and reporting.
  • Sanitization: There is no evidence of input validation or sanitization for the provided academic sources.
  • [NO_CODE]: The skill consists entirely of Markdown instructions and does not contain any executable scripts, binary files, or configuration for external package managers.
  • [EXTERNAL_DOWNLOADS]: The skill suggests using external academic services to verify bibliographic data.
  • Evidence: The instructions refer to using Crossref, DataCite, Semantic Scholar, and OpenAlex for metadata lookup and DOI resolution. These are established well-known services in the academic community.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 03:00 AM
Security Audit — agent-trust-hub — citation-check