scholar-publish

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user input (academic papers) to generate summaries and promotional materials. It lacks explicit boundary markers or sanitization, creating a surface for indirect prompt injection if a source document contains adversarial instructions intended to influence the agent's behavior. 1. Ingestion points: User-provided paper text and file paths ingested during the initial processing and presentation phases. 2. Boundary markers: Absent; source text is not isolated with delimiters. 3. Capability inventory: The skill has access to tools including Bash, Read, Write, and Edit. 4. Sanitization: Paper content is processed without filtering or validation.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute maestro commands for loading coding specifications and searching academic writing guidelines. These operations are used for context enrichment and do not involve downloading or executing untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 12:17 PM
Security Audit — agent-trust-hub — scholar-publish