scientific-writing

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute local scripts and compile documents. This includes running python scripts for schematic generation and using the xelatex compiler for producing PDFs. These operations are within the expected scope of a document generation and scientific reporting tool.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection as it processes untrusted data from external sources. * Ingestion points: Data retrieved via the research-lookup tool is used to construct outlines and flowing prose in SKILL.md. * Boundary markers: There are no specific delimiters or instructions to ignore embedded commands when the agent processes literature search results. * Capability inventory: The skill has access to Bash, Read, Write, and Edit tools. * Sanitization: No sanitization logic is described for the text ingested from external research papers.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 08:21 AM
Security Audit — agent-trust-hub — scientific-writing