plos-medicine

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to ingest data from external sources and local repository files, creating a potential surface for indirect prompt injection if those sources were compromised.
  • Ingestion points: The instructions require the agent to read ../../resources/source-basis.md and ../../resources/official-source-map.md, and to perform live web searches for current journal guidelines.
  • Boundary markers: No specific delimiters or warnings to ignore embedded instructions are provided for these data sources.
  • Capability inventory: The skill is designed for agents with file-reading and web-searching capabilities.
  • Sanitization: No content filtering or validation is mentioned.
  • [NO_CODE]: The skill consists solely of markdown instructions and metadata. It does not include any scripts, executables, or package dependencies, which significantly limits the attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 11:33 AM
Security Audit — agent-trust-hub — plos-medicine