nature-ecology-and-evolution

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data (manuscripts and conceptual claims) to evaluate their fit for a specific journal. It possesses capabilities to read local project files (e.g., ../../resources/source-basis.md) and perform web searches for live instructions.
  • Ingestion points: User-provided manuscript text, target venue names, and conceptual claims in SKILL.md sections like 'When to trigger'.
  • Boundary markers: None explicitly defined in the instructions to separate manuscript content from agent instructions.
  • Capability inventory: File read access to relative paths and web search capabilities for retrieving live guidelines.
  • Sanitization: The skill lacks explicit sanitization or validation logic for the content of the manuscripts it processes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — nature-ecology-and-evolution