jacs-au

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-provided chemistry manuscripts, which are untrusted external data.
  • Ingestion points: The manuscript content is ingested and processed in the evaluation workflow to determine topic fit and evidence rigor.
  • Boundary markers: There are no delimiters or instructions provided to the agent to isolate the user input or ignore any potentially malicious instructions embedded within the manuscript.
  • Capability inventory: The skill performs text analysis, venue routing, and recommends searching external sites for submission guidelines.
  • Sanitization: The skill does not define any sanitization, filtering, or validation for the input manuscript text.
  • [DATA_EXFILTRATION]: The skill uses directory traversal to access shared resource files.
  • Evidence: The instructions point to '../../resources/source-basis.md' and '../../resources/official-source-map.md'.
  • Detail: While these likely refer to internal documentation, referencing files in parent directories using relative paths is a common pattern for accessing data outside the intended skill scope, which could potentially expose sensitive platform configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — jacs-au