slr-prisma
Warn
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute a Python script at
scripts/office/validate.pyduring Phase 5. This script is not included in the provided file set, making it an unverifiable local dependency. - [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface in Phase 1 (Interview), where it reads untrusted user-uploaded documents such as research proposals, PROSPERO registrations, and data extraction spreadsheets in formats like .docx, .pdf, and .xlsx. There are no boundary markers or sanitization steps mentioned to prevent embedded instructions in these files from overriding the agent's behavior during the drafting phases. The skill has access to sensitive capabilities including command execution and the
web_searchtool. - [DATA_EXFILTRATION]: The skill uses the
web_searchtool to verify academic citations and references. This involves transmitting user-provided reference data to external search engines. - [DATA_EXPOSURE]: The skill's core workflow requires reading and extracting data from potentially sensitive, unpublished academic manuscripts and research protocols.
Audit Metadata