academic-chapter-writer

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection due to its core functionality of ingesting and processing data from external sources.
  • Ingestion points: The skill retrieves data from the external PubMed MCP tool via the search_articles and get_article_metadata functions (referenced in SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or "ignore instructions" wrappers for data returned from the PubMed tool.
  • Capability inventory: The agent has network access (via the PubMed tool) and the ability to generate and format large volumes of markdown content.
  • Sanitization: There is no evidence of sanitization or strict schema validation for the metadata retrieved from PubMed before it is interpolated into the agent's writing workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 03:35 PM
Security Audit — agent-trust-hub — academic-chapter-writer