hypothesis-generation

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from local JSON, CSV, and Markdown files through various validation scripts.\n
  • Ingestion points: Scripts such as validate_hypothesis_schema.py, audit_evidence_ledger.py, and check_operationalization.py ingest user-controlled data to perform validation.\n
  • Boundary markers: The SKILL.md instructions emphasize "Non-negotiable boundaries" and "human accountability," providing context for the agent to treat data as candidate propositions rather than established facts.\n
  • Capability inventory: The skill utilizes local file read/write operations and command-line execution of bundled Python scripts.\n
  • Sanitization: Bundled scripts perform structural, type, and format validation via scripts/_common.py. The generate_preregistration_scaffold.py script applies HTML and Markdown escaping to generated content.\n- [COMMAND_EXECUTION]: The skill instructs the agent to execute bundled Python scripts for scientific data validation and report generation.\n
  • Evidence: Multiple commands are documented in SKILL.md, including python3 scripts/check_operationalization.py and python3 scripts/audit_evidence_ledger.py.\n
  • Mitigation: The Python scripts are local-only, depend solely on the standard library, and implement strict input validation to prevent common command-line vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — hypothesis-generation