paper-narrative
Pass
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external scientific manuscripts, abstracts, and figures. This creates a potential surface for indirect prompt injection where instructions embedded within the user-provided documents could attempt to influence the agent's behavior.
- Ingestion points: SKILL.md describes processing central claims, evidence chains, and manuscript drafts.
- Boundary markers: None mentioned.
- Capability inventory: The skill delegates work to other specialized tools (figure-composer, figure-style) but lacks internal capabilities for command execution or network access.
- Sanitization: No sanitization of external content is specified.
- [NO_CODE]: The skill consists entirely of descriptive natural language instructions and YAML metadata. It does not include any scripts, binaries, or shell commands that could be used to perform malicious actions.
Audit Metadata