scholar-evaluation

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze scholarly works (papers, drafts, protocols) and associated metadata provided by the user or external sources. This creates an attack surface where malicious instructions could be embedded in the research content to influence the agent's behavior.
  • Ingestion points: Processes user-supplied scholarly works, draft papers, and research data via JSON/CSV templates as described in the SKILL.md workflow.
  • Boundary markers: Implements safety boundaries in SKILL.md and references/responsible_assessment.md that explicitly instruct the agent to avoid high-impact decisions, ranking individuals, or inferring character traits.
  • Capability inventory: Utilizes Read, Write, Bash, Glob, and Python tools to execute local validation and scoring scripts. The scripts are dependency-free and do not use network or subprocess modules.
  • Sanitization: Scripts in the scripts/ directory perform structural validation, enforce size/depth limits, and use a blacklist (PRIVATE_FIELD_KEYS in _common.py) to reject sensitive data fields like SSNs, emails, or applicant names. Metadata references are further constrained to prevent URL or file protocol injection.
  • [COMMAND_EXECUTION]: The skill executes local Python scripts using the Bash tool to perform evaluation tasks. While these operations are constrained to local scripts using standard library functions, they represent the execution of logic on the host system.
  • Evidence: SKILL.md workflow steps demonstrate the use of python3 scripts/*.py commands for rubric validation, scoring, and report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scholar-evaluation