nature-neuroscience
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to evaluate untrusted user data (manuscripts) against journal-specific criteria, creating a potential vector for indirect prompt injection.
- Ingestion points: The skill processes manuscript text, framing, and data descriptions provided by the user in the agent context (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or specific safety instructions to isolate user-provided content from the agent's internal logic.
- Capability inventory: The skill directs the agent to perform external web searches for live journal instructions and read internal resource files (
../../resources/source-basis.md,../../resources/official-source-map.md). - Sanitization: There are no explicit instructions for sanitizing or validating user input before processing or using it to drive downstream searches.
Audit Metadata