asreview-systematic-review
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to process external, untrusted data from CSV files (titles and abstracts). While there are no explicit boundary markers or sanitization steps for the data content described in the documentation, the primary interaction is via the external
asreviewCLI tool. This represents a theoretical surface for indirect prompt injection, but it is inherent to the intended use case of literature screening. - [COMMAND_EXECUTION]: The skill provides examples of using the Python
subprocessmodule and shell commands to interact with theasreviewCLI. These are standard integration patterns for the documented tool and are used to facilitate simulation and data analysis tasks.
Audit Metadata