create-paper

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust 'Human-in-the-Loop' philosophy, requiring explicit user approval at multiple stages (Scope, Analysis, Literature, Learning, Draft) before proceeding.
  • [PROMPT_INJECTION]: The skill contains a dedicated sanitization module in utils.py and compliance.py specifically designed to detect and redact prompt injection patterns (e.g., 'ignore previous instructions', 'you are now') and hidden text techniques (zero-width characters, LaTeX white-text hiding).
  • [COMMAND_EXECUTION]: Orchestrates various local skills (assess, dogpile, arxiv, memory, fixture-graph) using subprocess.run. Command arguments are constructed from validated internal configurations rather than raw user input, mitigating risk of command injection.
  • [EXTERNAL_DOWNLOADS]: Fetches academic metadata and paper information from well-known services including the arXiv API, CrossRef API, and Semantic Scholar. These operations are performed via httpx with neutral data-fetching intent.
  • [SAFE]: Includes a 'Quality Dashboard' and verification tools to detect hallucinated references or ungrounded claims, ensuring the output aligns with the analyzed codebase.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — create-paper