scientific-brainstorming

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: Extensive analysis of the skill's instructions and bundled scripts revealed no malicious patterns. The skill maintainer (Kalaris Labs) implements robust safety controls for all local operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (CSV and JSON) through its evaluation and validation scripts, creating a potential surface for indirect prompt injection. This risk is well-mitigated by the skill's architecture:
  • Ingestion points: scripts/evaluate_matrix.py reads user-supplied CSV and JSON files; scripts/validate_register.py reads JSON session registers.
  • Boundary markers: The agent instructions in SKILL.md explicitly enforce the separation and labeling of different information types (e.g., idea, assumption, prediction, decision), reducing context confusion.
  • Capability inventory: Capabilities are limited to local file read/write operations and deterministic data processing. The skill does not perform network requests or execute arbitrary code from the processed data.
  • Sanitization: The scripts/_common.py utility module provides significant hardening. It uses O_NOFOLLOW and stat.S_ISREG to prevent symlink and non-regular file attacks, enforces text length limits (e.g., MAX_TEXT_CHARS = 10_000), validates identifiers with strict regex, and ensures output files are created with private permissions (0o600).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scientific-brainstorming