venue-templates

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a repository for academic formatting templates and writing guidelines. All analyzed files are consistent with this purpose and do not contain malicious code, hidden instructions, or unauthorized data access patterns.
  • [COMMAND_EXECUTION]: The helper script validate_format.py uses the subprocess module to execute Poppler PDF utilities (pdfinfo, pdffonts). These executions are performed securely by passing arguments as a list, preventing shell injection vulnerabilities from user-provided file paths.
  • [INDIRECT_PROMPT_INJECTION]: The skill involves the agent reading external venue websites and processing user-supplied manuscript metadata. The instructions provide clear boundaries, directing the agent to prioritize official sources over summarized references and to treat bundled templates as drafting scaffolds, which reduces the impact of potentially adversarial data in external guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 03:50 PM
Security Audit — agent-trust-hub — venue-templates