nature-medicine
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze user-supplied scientific manuscripts and clinical trial data to determine journal fit. This ingestion of untrusted content, combined with capabilities like web searching for official guidelines and reading local resource files, creates a surface for indirect prompt injection.
- Ingestion points: User-provided manuscripts, trial data, and study descriptions entered into the agent context.
- Boundary markers: The skill instructions do not specify the use of delimiters or 'ignore' commands to isolate untrusted input.
- Capability inventory: The skill references reading local files (
../../resources/source-basis.md) and instructs the agent to perform live web searches for 'Nature Medicine author information'. - Sanitization: No sanitization or validation of input data is defined in the instructions.
Audit Metadata