ma-end-to-end

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes official package managers (uv for Python, renv for R) to manage dependencies from standard registries like PyPI and CRAN. It references the well-known R metadat package and its official documentation, which are trusted scientific resources.
  • [COMMAND_EXECUTION]: The orchestration scripts execute local Python and R components to automate project initialization, checkpointing, and data analysis. These operations are performed within the isolated project context and are essential for the skill's stated purpose.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted external literature data (search results and full-text PDFs).
  • Ingestion points: TOPIC.txt, BibTeX search results, and PDF full-texts.
  • Boundary markers: Numbered project structure and mandatory stage-transition validation reports.
  • Capability inventory: Subprocess execution for data processing scripts and Quarto manuscript rendering.
  • Sanitization: Implements manual dual-review checkpoints (screening), PRISMA reporting audits, and SHA-256 artifact hashing to ensure traceability and result integrity.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 03:00 AM
Security Audit — agent-trust-hub — ma-end-to-end