peer-review

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external manuscripts, reference lists (CSV), and review checklists (JSON), which represent untrusted data ingestion surfaces.
  • Ingestion points: Multiple scripts ingest external data, including scripts/audit_citations.py (Markdown/CSV), scripts/audit_statistics_reproducibility.py (JSON), scripts/validate_claim_evidence.py (CSV), and scripts/lint_review.py (Markdown).
  • Boundary markers: The skill instructions include a mandatory safety boundary section requiring authorization confirmation. The tools are explicitly designed to emit structured reports (identifiers and counts) rather than echoing raw manuscript content, reducing the risk of accidental instruction obedience.
  • Capability inventory: All bundled tools are deterministic Python scripts using only the standard library. No network access, subprocess execution, or dynamic code execution capabilities were detected across the script suite.
  • Sanitization: Input data is validated against strict schemas with defined limits on file size (4MiB), row counts (5,000), and cell length (12,000 characters) as implemented in scripts/_common.py. The scripts also reject symlink inputs to prevent path traversal or unauthorized file access.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — peer-review