paper-writer
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell access as a fallback mechanism to interact with scholarly APIs such as Crossref and Semantic Scholar for literature retrieval.
- [EXTERNAL_DOWNLOADS]: Fetches research metadata and abstracts from well-known scholarly indexes and public APIs during the literature search process.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted research materials from the user's workspace and external papers.
- Ingestion points: User-provided manuscript materials and external literature retrieved via research tools.
- Boundary markers: The skill employs an 'Evidence Map' and 'Verification Ladder' to validate claims, though no explicit technical delimiters are defined to isolate untrusted instructions.
- Capability inventory: The agent can generate files in the workspace, invoke fresh-context sub-agents, and execute shell commands.
- Sanitization: It implements a strict 'Evidence Discipline' to ensure output is grounded in verifiable sources, which serves as a semantic filter against hallucinated or injected content.
Audit Metadata