cn-thesis-data-figures
Pass
Audited by Gen Agent Trust Hub on Aug 12, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is entirely instructional, providing a structured workflow for academic data processing and figure design without executing external scripts or accessing sensitive system resources.- [PROMPT_INJECTION]: No malicious override commands or safety bypass patterns were identified. The instructions focus on maintaining academic rigor and adhering to thesis standards.- [DATA_EXFILTRATION]: No network operations (such as curl or wget) or attempts to access sensitive credentials or private system files were found.- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided datasets (an ingestion surface for untrusted data), it includes specific 'boundaries' that instruct the agent not to invent data, sample sizes, or significance values. It also requires the use of '[TBD]' placeholders for missing numeric evidence, which serves as a grounding mechanism against data-driven injection attacks.- [EXTERNAL_DOWNLOADS]: The skill references internal shared configuration files via relative paths in the manifest.yaml file (e.g., '../../shared/core/'). This is a standard modular architecture and does not involve fetching resources from untrusted external domains.
Audit Metadata