citation-guard
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary functionality involves reading research sources and assessment guides from within the .aiwg/ project directory. These operations are restricted to the local workspace and do not involve sensitive system paths or credential access.
- [PROMPT_INJECTION]: The skill analyzes agent-generated text to identify and verify research citations. This constitutes a surface for indirect prompt injection, as the agent may process content from external sources. However, the skill's actions are limited to passive verification and local logging, which does not present a path for privilege escalation or malicious execution.
- Ingestion points: Agent-generated content containing patterns like REF-XXX or DOI (SKILL.md).
- Boundary markers: None identified.
- Capability inventory: Reading research files in .aiwg/research/ and writing to TODO.md (SKILL.md).
- Sanitization: None identified.
Audit Metadata