sr-screener

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external bibliographic data (RIS, NBIB, CSV, PDF) which represents a surface for indirect prompt injection.
  • Ingestion points: The scripts scripts/prepare_records.py and scripts/prepare_fulltext.py ingest data from bibliographic export files and PDF documents into the agent's context.
  • Boundary markers: The skill uses explicit delimiters (=== SCREENING PROTOCOL ... ===) in templates/prompts.md and contains system instructions in agents/screening_reviewer_agent.md and SKILL.md to treat retrieved content as data, not commands.
  • Capability inventory: The screening reviewer subagents are restricted to the Read and Grep tools. The Python scripts perform local file reading and writing. No remote command execution tools or network-enabled agents are involved in processing the untrusted data.
  • Sanitization: The scripts/srlib.py helper script implements the spreadsheet_text function, which escapes formula prefixes (=, +, -, @) in generated CSV and Excel logs to prevent spreadsheet injection attacks.
  • [DYNAMIC_EXECUTION]: The skill generates and executes JavaScript workflow scripts to orchestrate multi-agent screening tasks.
  • Evidence: The scripts/build_workflow.py script assembles JavaScript templates (ta_screening.template.js, ft_screening.template.js) with localized configuration to be run via the Workflow tool. This is the intended core functionality of the skill and is constructed using local templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 01:37 PM
Security Audit — agent-trust-hub — sr-screener