slr-prisma

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a Python script at scripts/office/validate.py during Phase 5. This script is not included in the provided file set, making it an unverifiable local dependency.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface in Phase 1 (Interview), where it reads untrusted user-uploaded documents such as research proposals, PROSPERO registrations, and data extraction spreadsheets in formats like .docx, .pdf, and .xlsx. There are no boundary markers or sanitization steps mentioned to prevent embedded instructions in these files from overriding the agent's behavior during the drafting phases. The skill has access to sensitive capabilities including command execution and the web_search tool.
  • [DATA_EXFILTRATION]: The skill uses the web_search tool to verify academic citations and references. This involves transmitting user-provided reference data to external search engines.
  • [DATA_EXPOSURE]: The skill's core workflow requires reading and extracting data from potentially sensitive, unpublished academic manuscripts and research protocols.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 03:11 AM
Security Audit — agent-trust-hub — slr-prisma