scholar-evaluation
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze scholarly works (papers, drafts, protocols) and associated metadata provided by the user or external sources. This creates an attack surface where malicious instructions could be embedded in the research content to influence the agent's behavior.
- Ingestion points: Processes user-supplied scholarly works, draft papers, and research data via JSON/CSV templates as described in the
SKILL.mdworkflow. - Boundary markers: Implements safety boundaries in
SKILL.mdandreferences/responsible_assessment.mdthat explicitly instruct the agent to avoid high-impact decisions, ranking individuals, or inferring character traits. - Capability inventory: Utilizes
Read,Write,Bash,Glob, andPythontools to execute local validation and scoring scripts. The scripts are dependency-free and do not use network or subprocess modules. - Sanitization: Scripts in the
scripts/directory perform structural validation, enforce size/depth limits, and use a blacklist (PRIVATE_FIELD_KEYSin_common.py) to reject sensitive data fields like SSNs, emails, or applicant names. Metadata references are further constrained to prevent URL or file protocol injection. - [COMMAND_EXECUTION]: The skill executes local Python scripts using the
Bashtool to perform evaluation tasks. While these operations are constrained to local scripts using standard library functions, they represent the execution of logic on the host system. - Evidence:
SKILL.mdworkflow steps demonstrate the use ofpython3 scripts/*.pycommands for rubric validation, scoring, and report generation.
Audit Metadata