nature-sustainability

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest and act upon data from external web searches and local resource files, which creates a potential surface for indirect prompt injection if the source content is maliciously crafted.
  • Ingestion points: The agent is instructed to read ../../resources/source-basis.md and ../../resources/official-source-map.md, and to perform live searches for "Nature Sustainability author instructions" on the Springer Nature website.
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" wrappers for the data retrieved from these sources.
  • Capability inventory: The skill utilizes file system read access for local resources and web search capabilities to retrieve external documentation.
  • Sanitization: There is no mention of sanitizing or validating the content retrieved from the web searches or local resource files before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — nature-sustainability