cell
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze manuscript data provided by the user. This creates an attack surface where maliciously crafted input (e.g., instructions hidden within a paper's abstract or results) could influence the agent's behavior. However, the skill's capabilities are limited to providing feedback and formatting text, which significantly mitigates the potential impact of such an injection.
- Ingestion points: The agent processes manuscript details, abstracts, and framing text provided by the author during the evaluation process.
- Boundary markers: No explicit delimiters or 'ignore' instructions are defined for the user-supplied content.
- Capability inventory: The skill is restricted to text analysis and heuristic-based suggestions; it lacks file-write, shell-execution, or non-whitelisted network capabilities.
- Sanitization: The skill does not implement specific sanitization or filtering logic for the input data.
Audit Metadata