ma-end-to-end
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes official package managers (
uvfor Python,renvfor R) to manage dependencies from standard registries like PyPI and CRAN. It references the well-known Rmetadatpackage and its official documentation, which are trusted scientific resources. - [COMMAND_EXECUTION]: The orchestration scripts execute local Python and R components to automate project initialization, checkpointing, and data analysis. These operations are performed within the isolated project context and are essential for the skill's stated purpose.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it processes untrusted external literature data (search results and full-text PDFs).
- Ingestion points:
TOPIC.txt, BibTeX search results, and PDF full-texts. - Boundary markers: Numbered project structure and mandatory stage-transition validation reports.
- Capability inventory: Subprocess execution for data processing scripts and Quarto manuscript rendering.
- Sanitization: Implements manual dual-review checkpoints (screening), PRISMA reporting audits, and SHA-256 artifact hashing to ensure traceability and result integrity.
Audit Metadata