academic-pipeline
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents an indirect prompt injection surface as it is designed to ingest and process untrusted third-party content from the web and uploaded documents. • Ingestion points: The
integrity_verification_agent.mdandclaim_ref_alignment_audit_agent.mdexplicitly use WebSearch tools to fetch external data and read local PDF files to verify academic citations and data claims. • Boundary markers: The skill implements mitigation strategies by including thecanonical:instruction-data-boundarypattern in several files (SKILL.md,integrity_verification_agent.md,claim_ref_alignment_audit_agent.md), instructing agents to treat external content as data rather than instructions. • Capability inventory: The orchestrator has the capability to modify project files viascripts/ars_apply_revision_patch.py, write state logs withscripts/run_ledger.py, and perform network operations via WebSearch and API calls. • Sanitization: The skill relies on prompt-based instructions to ignore imperative language in retrieved content, but lacks machine-level sanitization for ingested text. - [COMMAND_EXECUTION]: The orchestrator frequently executes local Python and Shell scripts within the project's
scripts/directory to manage the research workflow. Key scripts includescripts/run_ledger.pyfor session persistence,scripts/pdf_read_preflight.pyfor file analysis, andscripts/ars_apply_revision_patch.pyfor automated file editing. - [DATA_EXFILTRATION]: The skill includes an optional cross-model verification feature (
ARS_CROSS_MODEL) used by thecollaboration_depth_agentand theintegrity_verification_agent. This mode can send raw dialogue turns, which may contain private researcher reasoning or unpublished findings, to external model providers. This behavior is documented as requiring an explicit user consent gate before data transmission occurs.
Audit Metadata