astronomy-and-astrophysics
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from both internal resource files and external web searches, creating a surface for indirect prompt injection from potentially attacker-controlled content.
- Ingestion points: The instructions direct the agent to read local files (
../../resources/source-basis.mdand../../resources/official-source-map.md) and to "Search the live site for 'Astronomy & Astrophysics author guidelines' / 'A&A instructions for authors'" using available tools. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to ignore or isolate embedded instructions within the retrieved content.
- Capability inventory: The skill is primarily focused on text analysis and journal fit assessment; it does not demonstrate capabilities for subprocess execution, sensitive file writing, or network exfiltration of system credentials.
- Sanitization: The skill does not provide mechanisms for sanitizing or validating the content retrieved from external sources before it is processed by the agent.
Audit Metadata