source-comparison

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill acts as a comparison engine for external data (papers, tools, frameworks), which makes it susceptible to indirect prompt injection if the sources contain malicious instructions.\n
  • Ingestion points: The workflow ingests information from multiple user-provided sources as described in SKILL.md.\n
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the processed data mentioned in the file.\n
  • Capability inventory: The skill utilizes researcher and verifier agents and performs file-write operations to the outputs/ directory.\n
  • Sanitization: No sanitization or validation logic for the external source content is specified in the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 12:41 PM
Security Audit — agent-trust-hub — source-comparison