systematic-review-prisma
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements standard scientific workflows for literature reviews. The instructions guide users through protocol registration, database searching, and data synthesis using established methodologies.
- [SAFE]: The bundled Python scripts (
scripts/dedupe_records.pyandscripts/prisma_flow.py) rely exclusively on the Python standard library. They perform local data processing tasks (parsing RIS/CSV/BibTeX files and calculating counts for flow diagrams) without any network operations, external dependencies, or dynamic code execution. - [SAFE]: Data handling is performed using standard
argparse,csv, andjsonmodules. The scripts do not access sensitive file paths or credentials, focusing entirely on bibliographic data provided by the user. - [SAFE]: The external references provided (PROSPERO, OSF, PubMed, Embase, Scopus, Web of Science, and the PRISMA statement website) are well-known, trusted scientific and academic resources. No suspicious or obfuscated URLs were found.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied bibliographic data and count files. While this creates an ingestion surface for untrusted data, the skill lacks any dangerous capabilities (such as shell execution or network exfiltration) that could be exploited via indirect injection. The severity is safe.
Audit Metadata