academic-research-suite
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing untrusted external text such as research papers and reviewer comments.
- Ingestion points: Manuscripts and reviewer letters are processed by several agents, including
draft_writer_agent.md,eic_agent.md, anddevils_advocate_reviewer_agent.md. - Boundary markers: The skill uses explicit XML-style delimiters like
<paper_content>and<phase1_output>to separate untrusted data from system instructions. - Capability inventory: The skill utilizes
Bash(restricted topythonanduvcommands) andWebSearchfor research and formatting tasks. - Sanitization: The instructions contain strong, repeated directives to the AI to treat input within tags as non-executable data and specifically commands the agent to ignore common prompt injection phrases (like "ignore previous instructions") found in such data.
Audit Metadata