scientific-critical-thinking

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted scientific drafts and data provided by users to perform critical analysis, representing an inherent attack surface for indirect prompt injection.
  • Ingestion points: The skill instructions in SKILL.md require the agent to collect the "user's draft, data, figures and target venue" for analysis.
  • Boundary markers: The skill includes "Integrity rules" in SKILL.md that explicitly prohibit the agent from fabricating results or adding unapproved claims, which serve as behavioral delimiters.
  • Capability inventory: The skill is scoped with Read, Write, and Edit tools and includes procedural instructions for executing a local Python script.
  • Sanitization: No explicit content sanitization or escaping mechanisms are described for handling the user-provided inputs.
  • [COMMAND_EXECUTION]: The skill provides procedural guidance for executing a local Python script to generate scientific diagrams.
  • Evidence: SKILL.md contains a bash example: python skills/scientific-schematics/scripts/generate_schematic.py "..." -o ....
  • The script resides in the skills/scientific-schematics/ directory, identifying it as a related tool within the vendor's own repository scope.
  • [EXTERNAL_DOWNLOADS]: The skill documents the use of a third-party API for AI-generated visual aids.
  • Evidence: The skill mentions that outbound API access to openrouter.ai is required for schematic generation, as noted in the frontmatter and the "Visual Aids" disclosure section of SKILL.md.
  • OpenRouter is a well-known service for LLM API routing.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scientific-critical-thinking