academic-paper
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes multiple local Python scripts (e.g.,
scripts/run_ledger.py,scripts/ars_apply_revision_patch.py,scripts/verify_submission_package.py) for managing the state of the writing pipeline, applying patches, and verifying manuscript integrity. It also suggests the use of system tools such aspandocfor document conversion andtectonicfor LaTeX compilation.\n- [EXTERNAL_DOWNLOADS]: Thecitation_compliance_agentis designed to perform network lookups viaretractionwatch.comand DOI resolvers to verify the validity and retraction status of academic citations. This is a documented functional requirement for the skill's academic integrity features.\n- [INDIRECT_PROMPT_INJECTION]: The pipeline ingests untrusted third-party data, such as reviewer comments and literature abstracts. The skill incorporates a robust 'canonical:instruction-data-boundary' directive throughout its agents, instructing them to treat all retrieved content as data and never promote it to instructions, mitigating potential injection attacks.\n- [DYNAMIC_EXECUTION]: Thevisualization_agentgenerates executable Python (matplotlib/seaborn) or R (ggplot2) code for the creation of publication-quality figures based on data extracted from the manuscript or provided by the user.\n- [PROMPT_INJECTION]: The skill defines a[direct-mode]token in the routing logic ofSKILL.mdthat allows for bypassing standard clarification steps to route directly to specific agents. While a behavior override mechanism, it is an intentional internal control feature and does not appear to bypass safety protocols.
Audit Metadata