academic-paper-reviewer

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies submitted manuscripts and reviewer comments as untrusted data and includes explicit defensive instructions to prevent the agents from obeying any embedded directives found within these materials.
  • [DATA_EXFILTRATION]: The skill includes a cross-model calibration feature that involves sending manuscript data to external model providers to increase review accuracy. This is a documented feature controlled by a protocol that requires explicit user consent before data is transferred.
  • [COMMAND_EXECUTION]: Local Python scripts are utilized within the workflow for structural validation and integrity checks of the peer-review process, ensuring that the agents adhere to specific sprint contracts and phase boundaries.
  • [PROMPT_INJECTION]: Static analysis flags regarding instruction overrides were found to be false positives; the identified text consists of defensive commands instructing the agent to ignore imperative sentences inside data delimiters (e.g., <phase1_output>) to prevent prompt injection from previous session outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 07:12 AM
Security Audit — agent-trust-hub — academic-paper-reviewer