deep-research

Pass

Audited by Gen Agent Trust Hub on May 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the pdftotext system utility for automated metadata extraction.\n
  • As described in agents/timeline_extraction_agent.md, the utility is used to extract the first line of locally provided PDF documents to verify publication years.\n- [EXTERNAL_DOWNLOADS]: The agents perform network lookups against established academic registries and databases.\n
  • Verification protocols in references/crossref_api_protocol.md, references/openalex_api_protocol.md, and references/semantic_scholar_api_protocol.md involve connecting to these well-known services to confirm bibliographic accuracy and check for retracted papers.\n- [PROMPT_INJECTION]: The Socratic Mentor agent is subject to behavioral constraints designed to maintain academic rigor.\n
  • The agents/socratic_mentor_agent.md defines 'Anti-Sycophancy' and 'Anti-Premature-Closure' rules that instruct the model to resist default AI helpfulness biases in favor of probing the user's research reasoning. These are persona-level configurations, not attempts to bypass safety filters.\n- [SAFE]: The architecture demonstrates a strong focus on research integrity and safety through its multi-phase pipeline.\n
  • It includes mandatory 'Ethics Review' and 'Devil's Advocate' checkpoints that require user confirmation to proceed. It also enforces structured data markers (<!--ref:slug-->) to prevent hallucinated citations and ensure claim traceability.
Audit Metadata
Risk Level
SAFE
Analyzed
May 21, 2026, 05:53 PM
Security Audit — agent-trust-hub — deep-research