physical-review-letters

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-provided manuscripts to assess journal fit, which constitutes a potential surface for indirect prompt injection. However, this is inherent to the skill's primary function and no exploitable capabilities were found within the instructions.
  • Ingestion points: User-supplied manuscript content and abstracts (SKILL.md).
  • Boundary markers: Not specified within the skill instructions.
  • Capability inventory: No high-risk tools (network, shell execution, file system writes) are explicitly invoked by the skill.
  • Sanitization: No explicit input validation or sanitization logic is provided.
  • [SAFE]: A comprehensive analysis for malicious patterns including prompt injection, data exfiltration, obfuscation, persistence, and privilege escalation yielded no findings. The skill's reference to local resource files (../../resources/) is consistent with standard modular skill organization. The instructional tone is benign and focused entirely on the stated academic purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — physical-review-letters