skills/jmagly/aiwg/citation-backfill/Gen Agent Trust Hub

citation-backfill

Pass

Audited by Gen Agent Trust Hub on Jun 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified through the propagation of untrusted content across the research corpus.
  • Ingestion points: Files in .aiwg/research/citations/, .aiwg/research/findings/, and .aiwg/research/documentation/citations/ (SKILL.md).
  • Boundary markers: Absent. No delimiters or ignore instructions are provided for processed research data.
  • Capability inventory: Execution permits use of Read, Write, Glob, Grep, and Bash tools.
  • Sanitization: Absent. The process preserves and rewrites manually-added annotations and notes without validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 19, 2026, 12:38 PM
Security Audit — agent-trust-hub — citation-backfill