ljg-paper
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes academic papers from external URLs (e.g., Arxiv), PDFs, or local files. Maliciously crafted papers could attempt to include instructions to influence the agent's behavior or output structure.
- Ingestion points: External content is retrieved using
ljg-fetch,WebFetch, or local file reading in the "Get Content" step ofSKILL.md. - Boundary markers: The prompt instructions do not specify explicit delimiters or "ignore instructions" wrappers for the ingested paper text.
- Capability inventory: The skill possesses the capability to read local files/URLs and write synthesized analysis files to the local directory
~/Documents/notes/. - Sanitization: There is no evidence of explicit sanitization or filtering of the ingested academic content before processing.
Audit Metadata