academic-pipeline
Pass
Audited by Gen Agent Trust Hub on May 21, 2026
Risk Level: SAFE
Full Analysis
- [DATA_EXFILTRATION]: The skill identifies potentially sensitive information such as 'abstract' and 'user_notes' in the literature corpus and provides clear protocols for privacy clearing. It advises users on responsible sharing of Material Passports and ensures that data management remains local to the user's environment.
- [COMMAND_EXECUTION]: For core functions like PDF compilation and document format conversion, the skill utilizes local Python scripts and established CLI tools such as Tectonic and Pandoc. These operations are strictly bounded to the academic workflow and are documented within the skill's reference files.
- [PROMPT_INJECTION]: The skill processes untrusted data from external academic sources during literature reviews and integrity checks. It mitigates indirect prompt injection risks by using structured boundary markers like HTML comment citation tags to isolate metadata from the document body and follows rigorous verification protocols to inspect content for factual accuracy.
- [REMOTE_CODE_EXECUTION]: Verification agents within the skill interact with reputable academic APIs (e.g., Semantic Scholar) to validate citation data. The skill does not download or execute arbitrary remote code; all executable logic is contained within the localized script directory distributed with the skill package.
Audit Metadata