academic-search
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data through the
extract_text_from_pdftool for paper analysis and synthesis. This creates a surface where malicious instructions embedded in a document (e.g., hidden text in a PDF) could attempt to influence the agent's output or actions. - Ingestion points: The
extract_text_from_pdftool specified in themcpfrontmatter and referenced in Step 3 of the usage instructions. - Boundary markers: Absent. There are no instructions provided to the agent to use specific delimiters or to ignore potential instructions embedded within the ingested paper text.
- Capability inventory: The skill utilizes the
create_docxtool, allowing it to write to the file system based on processed input. - Sanitization: Absent. The skill does not define any sanitization, validation, or filtering logic for the text extracted from external documents.
Audit Metadata