skills/jmagly/aiwg/citation-guard/Gen Agent Trust Hub

citation-guard

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary functionality involves reading research sources and assessment guides from within the .aiwg/ project directory. These operations are restricted to the local workspace and do not involve sensitive system paths or credential access.
  • [PROMPT_INJECTION]: The skill analyzes agent-generated text to identify and verify research citations. This constitutes a surface for indirect prompt injection, as the agent may process content from external sources. However, the skill's actions are limited to passive verification and local logging, which does not present a path for privilege escalation or malicious execution.
  • Ingestion points: Agent-generated content containing patterns like REF-XXX or DOI (SKILL.md).
  • Boundary markers: None identified.
  • Capability inventory: Reading research files in .aiwg/research/ and writing to TODO.md (SKILL.md).
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 12:25 PM
Security Audit — agent-trust-hub — citation-guard