tw-research-ethics-reviewer

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance for IRB (Institutional Review Board) compliance in Taiwan. All instructions and templates are benign and intended for educational and academic research purposes.
  • [PROMPT_INJECTION]: No evidence of prompt injection or bypass instructions detected. The logic focuses entirely on research ethics evaluation.
  • [DATA_EXFILTRATION]: No network operations (curl, wget, etc.) or access to sensitive local file paths (e.g., .ssh, .env) were found. The skill does not attempt to send data externally.
  • [REMOTE_CODE_EXECUTION]: No remote script downloads or dynamic code execution patterns (eval, exec) are present.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it ingests user-provided research descriptions to generate reports. However, it lack dangerous capabilities like automated network exfiltration or command execution based on that input.
  • Ingestion points: Step 1 in SKILL.md asks for user research designs and data collection methods.
  • Boundary markers: Absent.
  • Capability inventory: The skill allows Bash, Read, Write tools in its configuration, but no scripts in the provided files utilize them for dangerous operations.
  • Sanitization: No explicit sanitization or filtering instructions for user input are defined.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 04:11 AM
Security Audit — agent-trust-hub — tw-research-ethics-reviewer