create-peer-review

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill orchestrates tasks by executing commands via subprocess.run to invoke other skills such as scillm and create-paper.
  • [PROMPT_INJECTION]: The skill documentation establishes a 'Pen Name Enforcement' policy that mandates specific identity mappings, acting as a behavioral constraint that overrides standard agent logic. Additionally, the skill is susceptible to indirect prompt injection from untrusted external content.
  • Ingestion points: Research paper text extracted from ArXiv in src/curriculum.py.
  • Boundary markers: Lacks explicit delimiters or instructions for the LLM to ignore embedded commands in paper content.
  • Capability inventory: Includes sub-process execution via uv run and file system writes for review reports and snapshots.
  • Sanitization: Relies on basic regex-based stripping of HTML and LaTeX tags.
  • [EXTERNAL_DOWNLOADS]: The skill retrieves paper content and metadata from well-known academic services including ar5iv.labs.arxiv.org and api.semanticscholar.org.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — create-peer-review