sr-screener
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external bibliographic data (RIS, NBIB, CSV, PDF) which represents a surface for indirect prompt injection.
- Ingestion points: The scripts
scripts/prepare_records.pyandscripts/prepare_fulltext.pyingest data from bibliographic export files and PDF documents into the agent's context. - Boundary markers: The skill uses explicit delimiters (
=== SCREENING PROTOCOL ... ===) intemplates/prompts.mdand contains system instructions inagents/screening_reviewer_agent.mdandSKILL.mdto treat retrieved content as data, not commands. - Capability inventory: The screening reviewer subagents are restricted to the
ReadandGreptools. The Python scripts perform local file reading and writing. No remote command execution tools or network-enabled agents are involved in processing the untrusted data. - Sanitization: The
scripts/srlib.pyhelper script implements thespreadsheet_textfunction, which escapes formula prefixes (=,+,-,@) in generated CSV and Excel logs to prevent spreadsheet injection attacks. - [DYNAMIC_EXECUTION]: The skill generates and executes JavaScript workflow scripts to orchestrate multi-agent screening tasks.
- Evidence: The
scripts/build_workflow.pyscript assembles JavaScript templates (ta_screening.template.js,ft_screening.template.js) with localized configuration to be run via theWorkflowtool. This is the intended core functionality of the skill and is constructed using local templates.
Audit Metadata