de-ai-skill

Pass

Audited by Gen Agent Trust Hub on Mar 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted user-provided academic text and has the capability to modify files, which presents a surface for indirect prompt injection.\n
  • Ingestion points: Reads text from files via the Read tool or from pasted text in the conversation.\n
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions to the agent to disregard any embedded commands within the text being analyzed.\n
  • Capability inventory: The skill uses the Edit tool to perform in-place modifications and uses Structured Interaction for workflow control.\n
  • Sanitization: There is no documented process for sanitizing or filtering input text before it is analyzed for linguistic patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 16, 2026, 12:17 PM