new-phytologist

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to retrieve and process content from the New Phytologist website, which introduces an indirect prompt injection attack surface where untrusted external data could influence agent behavior.
  • Ingestion points: The agent is instructed to search for and read 'live New Phytologist author guidelines' from the web (referenced in SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or safety headers to protect the agent's context from potential malicious instructions embedded in the external source material.
  • Capability inventory: The agent employs search tools to gather external data and accesses internal resource files such as '../../resources/source-basis.md'.
  • Sanitization: The skill does not specify any validation, filtering, or escaping mechanisms for the data retrieved from the journal's website.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:29 AM
Security Audit — agent-trust-hub — new-phytologist