journal-of-experimental-medicine

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions that lead the agent to ingest data from external and local sources, creating a potential surface for indirect prompt injection.
  • Ingestion points: The skill directs the agent to read resource files at ../../resources/source-basis.md and ../../resources/official-source-map.md, and to perform web searches for live author instructions on the Rockefeller University Press / JEM website.
  • Boundary markers: The skill does not provide explicit boundary markers or instructions to ignore potential commands embedded within the retrieved external content or files.
  • Capability inventory: The skill leverages web search and file reading capabilities. It does not appear to use high-risk capabilities like arbitrary command execution or network writes to untrusted domains.
  • Sanitization: No sanitization, validation, or filtering procedures for the external content were identified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — journal-of-experimental-medicine