astronomy-and-astrophysics

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from both internal resource files and external web searches, creating a surface for indirect prompt injection from potentially attacker-controlled content.
  • Ingestion points: The instructions direct the agent to read local files (../../resources/source-basis.md and ../../resources/official-source-map.md) and to "Search the live site for 'Astronomy & Astrophysics author guidelines' / 'A&A instructions for authors'" using available tools.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or isolate embedded instructions within the retrieved content.
  • Capability inventory: The skill is primarily focused on text analysis and journal fit assessment; it does not demonstrate capabilities for subprocess execution, sensitive file writing, or network exfiltration of system credentials.
  • Sanitization: The skill does not provide mechanisms for sanitizing or validating the content retrieved from external sources before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — astronomy-and-astrophysics