scientific-question

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied research topics, practical concerns, and draft aims to generate or refine questions, which constitutes a surface for indirect prompt injection.
  • Ingestion points: SKILL.md (Workflow section) instructs the agent to extract content from user input to identify the topic, system, and intended contribution.
  • Boundary markers: The instructions require the agent to distinguish between "verified evidence" and "user-reported but unchecked information" and to label synthetic instructional examples as "教学构造".
  • Capability inventory: The skill is composed of natural language instructions and does not include any scripts or tools for file system or network interaction.
  • Sanitization: The agent is instructed to report the search scope and limits for any novelty verification and to mark claims as unverified if search tools are unavailable or declined.
  • [EXTERNAL_DOWNLOADS]: The references/sources.md file contains links to academic journals, publishers, and scientific repositories, including DOI.org, PubMed, PLOS, SAGE, and various university domains. These links are provided as static references for academic transparency and do not involve script execution or automated package installation.
  • [NO_CODE]: The skill contains no executable scripts (Python, Node.js, Shell, etc.), relying entirely on natural language instructions for the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 10:02 AM
Security Audit — agent-trust-hub — scientific-question