rt-response-to-referees

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted external data (referee reports) and uses it to influence agent actions, including code execution. \n
  • Ingestion points: The skill ingests untrusted text from referee reports and editor comments provided by users during the drafting process. \n
  • Boundary markers: There are no specific boundary markers or instructions within the skill to delimit the untrusted referee text or to explicitly ignore instructions embedded within those reports. \n
  • Capability inventory: The skill instructs the agent to perform re-runs of empirical code using the target pack's skill and the rt-execution-bridge based on the feedback received. \n
  • Sanitization: No input sanitization, filtering, or validation is specified for the text contained within the reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 10:29 AM
Security Audit — agent-trust-hub — rt-response-to-referees