hypogenic

Pass

Audited by Gen Agent Trust Hub on Apr 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install the hypogenic package from PyPI and clone example datasets from the Chicago Human+AI Lab (ChicagoHAI) GitHub organization. These are recognized academic entities.
  • [COMMAND_EXECUTION]: The documentation includes instructions for executing shell scripts to set up and run the GROBID service for processing research literature in PDF format.
  • [PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by ingesting and processing external datasets and research papers for LLM analysis. 1. Ingestion points: The framework reads from training, validation, and test JSON files, as well as research paper PDFs. 2. Boundary markers: The prompt templates use basic headers to distinguish data samples but do not include explicit instructions for the LLM to ignore embedded commands within the ingested content. 3. Capability inventory: The skill interacts with external LLM APIs, writes results to the local file system, and executes service-management shell scripts. 4. Sanitization: No explicit sanitization or filtering of input data is documented in the provided configuration templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 16, 2026, 10:49 PM