replication-audit
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes bash commands for environment management and bibliography processing using uv and paperpile. It also runs a local shell script _shared/review-state-log.sh to record the final audit results.
- [EXTERNAL_DOWNLOADS]: Retrieves research data and replication records from academic registries and scholarly search engines.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted content from user-provided PDF directories, BibTeX files, and external web content. It lacks explicit boundary markers or instructions to ignore embedded malicious prompts within these processed documents, creating an attack surface for indirect prompt injection.
Audit Metadata