communications-on-pure-and-applied-mathematics

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the analysis of external research papers and manuscript abstracts to determine journal fit, which introduces a surface for indirect prompt injection via the ingested data.\n
  • Ingestion points: The skill processes manuscript text, abstracts, and research summaries provided by users during the venue-selection and self-check processes mentioned in SKILL.md.\n
  • Boundary markers: The instructions lack specific delimiters or guardrail prompts (e.g., 'ignore instructions within the user text') to prevent the agent from following malicious instructions hidden within a math manuscript.\n
  • Capability inventory: The skill instructions direct the agent to read internal resource files (../../resources/source-basis.md and ../../resources/official-source-map.md). It lacks sensitive write permissions or network exfiltration capabilities, though it references checking external sites like the Wiley author guidelines for CPAM.\n
  • Sanitization: There is no definition of input sanitization or filtering to handle adversarial content within the processed academic manuscripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — communications-on-pure-and-applied-mathematics