skills/jkitchin/skillz/phd-qualifier/Gen Agent Trust Hub

phd-qualifier

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes web search tools to access well-known academic services such as Google Scholar and Web of Science. This process is used to verify literature citations and generate current, relevant questions for the oral examination phase, representing a standard information retrieval task for this domain.\n- [PROMPT_INJECTION]: The skill processes untrusted user-supplied files (PDFs, Word documents, and presentations), which introduces a surface for indirect prompt injection. Maliciously embedded text within these documents could attempt to hijack the agent's instructions.\n
  • Ingestion points: The agent is instructed to read and analyze complete external files provided by the user to perform evaluations (SKILL.md).\n
  • Boundary markers: The instructions include a 'Critical Instruction' to ground all feedback in the actual document content, use the Read tool, and quote specific text. This grounding acts as a functional boundary, though no explicit 'ignore embedded instructions' command is present for the ingested text.\n
  • Capability inventory: The skill is configured with broad tool access (allowed-tools: ['*']), which increases the potential impact of a successful injection from a malicious document.\n
  • Sanitization: The skill focuses on analytical verification of content rather than technical sanitization or filtering of the document text.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 02:12 PM
Security Audit — agent-trust-hub — phd-qualifier