reproducibility-audit

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of instructional markdown designed to guide an agent through a reproducibility audit. It does not contain executable code, hardcoded credentials, or network requests.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves analyzing untrusted external content (papers, code, and data), which constitutes an indirect prompt injection surface.
  • Ingestion points: Research artifacts, source code, and configuration files provided for auditing (SKILL.md).
  • Boundary markers: Absent; there are no instructions to the agent to distinguish between its instructions and potential instructions embedded in the artifacts being audited.
  • Capability inventory: The agent is expected to identify and execute shell commands or code snippets derived from the artifacts ("map paper claims to executable steps", "log exact commands and outputs").
  • Sanitization: Absent; the skill does not specify validation or sanitization steps for the code or commands found within the audited artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 08:24 PM
Security Audit — agent-trust-hub — reproducibility-audit