elife
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest data from external sources, creating a potential surface for indirect prompt injection.
- Ingestion points: Instructions in SKILL.md direct the agent to read local resource files (
../../resources/source-basis.md,../../resources/official-source-map.md) and searchelifesciences.orgfor live author instructions. - Boundary markers: Absent. There are no instructions to use delimiters or to treat the ingested external content as non-authoritative data.
- Capability inventory: The skill does not include capabilities for arbitrary command execution, network exfiltration, or sensitive file writing, which limits the risk profile.
- Sanitization: No validation or sanitization routines are specified for the external content before it is processed by the agent.
Audit Metadata