jacs-au
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided chemistry manuscripts, which are untrusted external data.
- Ingestion points: The manuscript content is ingested and processed in the evaluation workflow to determine topic fit and evidence rigor.
- Boundary markers: There are no delimiters or instructions provided to the agent to isolate the user input or ignore any potentially malicious instructions embedded within the manuscript.
- Capability inventory: The skill performs text analysis, venue routing, and recommends searching external sites for submission guidelines.
- Sanitization: The skill does not define any sanitization, filtering, or validation for the input manuscript text.
- [DATA_EXFILTRATION]: The skill uses directory traversal to access shared resource files.
- Evidence: The instructions point to '../../resources/source-basis.md' and '../../resources/official-source-map.md'.
- Detail: While these likely refer to internal documentation, referencing files in parent directories using relative paths is a common pattern for accessing data outside the intended skill scope, which could potentially expose sensitive platform configuration files.
Audit Metadata