source-comparison
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill acts as a comparison engine for external data (papers, tools, frameworks), which makes it susceptible to indirect prompt injection if the sources contain malicious instructions.\n
- Ingestion points: The workflow ingests information from multiple user-provided sources as described in SKILL.md.\n
- Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the processed data mentioned in the file.\n
- Capability inventory: The skill utilizes researcher and verifier agents and performs file-write operations to the outputs/ directory.\n
- Sanitization: No sanitization or validation logic for the external source content is specified in the skill's instructions.
Audit Metadata