paper-proofread

Pass

Audited by Gen Agent Trust Hub on May 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill analyzes user-provided LaTeX files, which represents a potential surface for indirect prompt injection. This risk is effectively mitigated by the skill's mandatory two-phase protocol: Phase 1 is restricted to detection and reporting, while Phase 2 requires explicit user confirmation for each specific fix before any file modifications are applied.
  • [DATA_EXFILTRATION]: The tool reads LaTeX source files, bibliographies, and macro definitions to perform its proofreading tasks. This data access is strictly scoped to the user's project files and is necessary for the skill's intended functionality.
  • [COMMAND_EXECUTION]: The skill includes instructions for the agent to modify files in Phase 2. This capability is gated behind a human-in-the-loop requirement where the user must approve specific issue IDs or categories before the agent proceeds with edits.
Audit Metadata
Risk Level
SAFE
Analyzed
May 13, 2026, 03:16 AM
Security Audit — agent-trust-hub — paper-proofread