plos-medicine
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest data from external sources and local repository files, creating a potential surface for indirect prompt injection if those sources were compromised.
- Ingestion points: The instructions require the agent to read
../../resources/source-basis.mdand../../resources/official-source-map.md, and to perform live web searches for current journal guidelines. - Boundary markers: No specific delimiters or warnings to ignore embedded instructions are provided for these data sources.
- Capability inventory: The skill is designed for agents with file-reading and web-searching capabilities.
- Sanitization: No content filtering or validation is mentioned.
- [NO_CODE]: The skill consists solely of markdown instructions and metadata. It does not include any scripts, executables, or package dependencies, which significantly limits the attack surface.
Audit Metadata