paper-writer

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell access as a fallback mechanism to interact with scholarly APIs such as Crossref and Semantic Scholar for literature retrieval.
  • [EXTERNAL_DOWNLOADS]: Fetches research metadata and abstracts from well-known scholarly indexes and public APIs during the literature search process.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes untrusted research materials from the user's workspace and external papers.
  • Ingestion points: User-provided manuscript materials and external literature retrieved via research tools.
  • Boundary markers: The skill employs an 'Evidence Map' and 'Verification Ladder' to validate claims, though no explicit technical delimiters are defined to isolate untrusted instructions.
  • Capability inventory: The agent can generate files in the workspace, invoke fresh-context sub-agents, and execute shell commands.
  • Sanitization: It implements a strict 'Evidence Discipline' to ensure output is grounded in verifiable sources, which serves as a semantic filter against hallucinated or injected content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 01:23 PM
Security Audit — agent-trust-hub — paper-writer