academic-search

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data through the extract_text_from_pdf tool for paper analysis and synthesis. This creates a surface where malicious instructions embedded in a document (e.g., hidden text in a PDF) could attempt to influence the agent's output or actions.
  • Ingestion points: The extract_text_from_pdf tool specified in the mcp frontmatter and referenced in Step 3 of the usage instructions.
  • Boundary markers: Absent. There are no instructions provided to the agent to use specific delimiters or to ignore potential instructions embedded within the ingested paper text.
  • Capability inventory: The skill utilizes the create_docx tool, allowing it to write to the file system based on processed input.
  • Sanitization: Absent. The skill does not define any sanitization, validation, or filtering logic for the text extracted from external documents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 04:11 PM
Security Audit — agent-trust-hub — academic-search