scientific-brainstorming
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: Extensive analysis of the skill's instructions and bundled scripts revealed no malicious patterns. The skill maintainer (Kalaris Labs) implements robust safety controls for all local operations.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (CSV and JSON) through its evaluation and validation scripts, creating a potential surface for indirect prompt injection. This risk is well-mitigated by the skill's architecture:
- Ingestion points:
scripts/evaluate_matrix.pyreads user-supplied CSV and JSON files;scripts/validate_register.pyreads JSON session registers. - Boundary markers: The agent instructions in
SKILL.mdexplicitly enforce the separation and labeling of different information types (e.g., idea, assumption, prediction, decision), reducing context confusion. - Capability inventory: Capabilities are limited to local file read/write operations and deterministic data processing. The skill does not perform network requests or execute arbitrary code from the processed data.
- Sanitization: The
scripts/_common.pyutility module provides significant hardening. It usesO_NOFOLLOWandstat.S_ISREGto prevent symlink and non-regular file attacks, enforces text length limits (e.g.,MAX_TEXT_CHARS = 10_000), validates identifiers with strict regex, and ensures output files are created with private permissions (0o600).
Audit Metadata