paper-corpus-rag

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (research papers) which could potentially contain malicious instructions targeting the LLM.
  • Ingestion points: scripts/paper_index.py reads content from files in a user-provided directory (papers/).
  • Boundary markers: SKILL.md includes grounding instructions for the agent (e.g., "Answer only from retrieved text", "Do not fill gaps from memory").
  • Capability inventory: The skill is restricted to file reading, local SQLite indexing, and querying; it lacks network access or sensitive file write capabilities.
  • Sanitization: The Python script implements a query tokenizer (fts_query) and uses parameterized SQL queries to prevent technical injection into the database engine.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill operates locally on the user's filesystem and uses standard libraries for its intended purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — paper-corpus-rag