ljg-xray-paper
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill accesses sensitive personal files located in the user's home directory to establish a cognitive baseline for analysis.\n
- Evidence: The 'L1: Cognitive Baseline Loading' section in SKILL.md requires the agent to read ~/Documents/know/soul.md (containing worldview and core beliefs) and ~/Documents/know/memory.md (containing long-term memory) before performing analysis.\n- [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes untrusted external content, creating a surface for indirect prompt injection attacks.\n
- Ingestion points: Full-text content is fetched from arXiv HTML versions or local PDF files via Step 1 in SKILL.md.\n
- Boundary markers: Absent. There are no instructions provided to the agent to treat the fetched paper content as data rather than instructions, nor are there delimiters used to wrap the input.\n
- Capability inventory: The agent has the capability to read sensitive local personal files (soul.md, memory.md) and write report files to ~/Documents/notes/ as described in Step 5 of SKILL.md.\n
- Sanitization: Absent. The skill does not define any validation or filtering for the external paper content before it is processed by the agent.
Audit Metadata