ljg-xray-paper

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill accesses sensitive personal files located in the user's home directory to establish a cognitive baseline for analysis.\n
  • Evidence: The 'L1: Cognitive Baseline Loading' section in SKILL.md requires the agent to read ~/Documents/know/soul.md (containing worldview and core beliefs) and ~/Documents/know/memory.md (containing long-term memory) before performing analysis.\n- [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes untrusted external content, creating a surface for indirect prompt injection attacks.\n
  • Ingestion points: Full-text content is fetched from arXiv HTML versions or local PDF files via Step 1 in SKILL.md.\n
  • Boundary markers: Absent. There are no instructions provided to the agent to treat the fetched paper content as data rather than instructions, nor are there delimiters used to wrap the input.\n
  • Capability inventory: The agent has the capability to read sensitive local personal files (soul.md, memory.md) and write report files to ~/Documents/notes/ as described in Step 5 of SKILL.md.\n
  • Sanitization: Absent. The skill does not define any validation or filtering for the external paper content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:50 PM
Security Audit — agent-trust-hub — ljg-xray-paper