joap-data-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface because it is designed to ingest and process user-provided research data and manuscript content which may contain malicious instructions.
  • Ingestion points: The skill processes user-supplied statistical results, data descriptions, and manuscript drafts to verify reporting norms (file: SKILL.md).
  • Boundary markers: No specific boundary markers or instructions to ignore embedded commands in the processed data are provided.
  • Capability inventory: The skill references an 'Execution bridge' that suggests executing complex statistical functions and analysis batteries via an external bridge (file: SKILL.md).
  • Sanitization: No data sanitization or input validation steps are mentioned for the processed data.
  • [COMMAND_EXECUTION]: The skill integrates with an external execution bridge for running statistical code.
  • Evidence: The skill references an 'Execution bridge' and specifies functions such as romano_wolf, benjamini_hochberg, and audit_result to be used for data analysis and reporting.
  • [EXTERNAL_DOWNLOADS]: The skill recommends several well-known third-party statistical packages.
  • Evidence: Mentions established tools like Mplus, lavaan, lme4, nlme, psych, metafor, and metaSEM for various statistical modeling tasks (file: SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 04:24 AM
Security Audit — agent-trust-hub — joap-data-analysis