scientific-writing

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements strong security boundaries by restricting all data processing to the local environment. The Python scripts in the scripts/ directory use only standard library modules and include safety limits on file sizes (5MB), JSON nesting (50 levels), and record counts (10,000) to prevent denial-of-service attacks. Additionally, the scripts explicitly reject symbolic links and use exclusive file creation modes to prevent accidental overwriting of data.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection as it ingests manuscript Markdown, JSON manifest files, and CSV claim registries. This risk is mitigated by the skill's operational design, which requires humans to remain accountable for all scientific content and verification.
  • Ingestion points: read_text, read_json, and read_csv in scripts/_common.py load user-supplied manuscript and registry files.
  • Boundary markers: The instructions utilize specific formatting patterns like [claim:C001] and [evidence:E001] for evidence binding, which helps distinguish identifiers from narrative content.
  • Capability inventory: The skill performs local file reading, schema validation, and text generation. It lacks capabilities for network access, arbitrary shell command execution, or dynamic code evaluation.
  • Sanitization: The provided tools perform strict regex-based validation of IDs (e.g., C001, E001, DOI) and schema enforcement for all structured input files.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — scientific-writing