academic-research-suite

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves processing untrusted external text such as research papers and reviewer comments.
  • Ingestion points: Manuscripts and reviewer letters are processed by several agents, including draft_writer_agent.md, eic_agent.md, and devils_advocate_reviewer_agent.md.
  • Boundary markers: The skill uses explicit XML-style delimiters like <paper_content> and <phase1_output> to separate untrusted data from system instructions.
  • Capability inventory: The skill utilizes Bash (restricted to python and uv commands) and WebSearch for research and formatting tasks.
  • Sanitization: The instructions contain strong, repeated directives to the AI to treat input within tags as non-executable data and specifically commands the agent to ignore common prompt injection phrases (like "ignore previous instructions") found in such data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:40 AM
Security Audit — agent-trust-hub — academic-research-suite