paper-lab
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill architecture describes an automated 'Fix Phase' where it ingests untrusted data from document files and associated source code to generate and apply edits via an LLM. This design creates a surface for indirect prompt injection, where malicious instructions embedded in the analyzed code or documentation could influence the agent's behavior during the headless convergence loop. Ingestion points: Document files processed by the tune command and any source code referenced for alignment. Boundary markers: The specification mentions using markdown comments for attribution but does not define robust delimiters to prevent the agent from following instructions found in the data. Capability inventory: The skill utilizes Write, Edit, and Bash tools to perform automated updates. Sanitization: No specific sanitization or validation of the content ingested from the external files is mentioned.
- [COMMAND_EXECUTION]: The skill requests the Bash tool and outlines a process for automated file modifications and subprocess calls to other skills like review-paper and create-paper during its iterative loop.
Audit Metadata