academic-paper-reviewer
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: Static analysis detections for instruction overrides (e.g., 'ignore previous instructions') are false positives in this context. These phrases appear within sophisticated 'Sprint Contract Protocols' designed to defend against indirect prompt injection. The skill explicitly instructs agents to treat data within delimiters as read-only and to ignore any imperative commands found therein, which is a security best practice for agents processing untrusted data.
- [COMMAND_EXECUTION]: The skill includes clear 'READ-ONLY' constraints (e.g., Checkpoint Rule #6 in SKILL.md) prohibiting agents from modifying source manuscripts. No dangerous shell commands, privilege escalation attempts, or persistence mechanisms were found.
- [DATA_EXFILTRATION]: There are no indicators of sensitive data exfiltration or hardcoded credentials. The skill's operations are limited to analyzing academic content and generating review reports within the platform's standard file structure.
- [EXTERNAL_DOWNLOADS]: The skill references established academic standards (APA 7.0) and reputable journals (Springer, Nature, Elsevier) for role calibration. No downloads or remote script executions from untrusted sources were identified.
Audit Metadata