joap-data-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 24, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface because it is designed to ingest and process user-provided research data and manuscript content which may contain malicious instructions.
- Ingestion points: The skill processes user-supplied statistical results, data descriptions, and manuscript drafts to verify reporting norms (file: SKILL.md).
- Boundary markers: No specific boundary markers or instructions to ignore embedded commands in the processed data are provided.
- Capability inventory: The skill references an 'Execution bridge' that suggests executing complex statistical functions and analysis batteries via an external bridge (file: SKILL.md).
- Sanitization: No data sanitization or input validation steps are mentioned for the processed data.
- [COMMAND_EXECUTION]: The skill integrates with an external execution bridge for running statistical code.
- Evidence: The skill references an 'Execution bridge' and specifies functions such as
romano_wolf,benjamini_hochberg, andaudit_resultto be used for data analysis and reporting. - [EXTERNAL_DOWNLOADS]: The skill recommends several well-known third-party statistical packages.
- Evidence: Mentions established tools like
Mplus,lavaan,lme4,nlme,psych,metafor, andmetaSEMfor various statistical modeling tasks (file: SKILL.md).
Audit Metadata