de-ai-skill
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted user-provided academic text and has the capability to modify files, which presents a surface for indirect prompt injection.\n
- Ingestion points: Reads text from files via the
Readtool or from pasted text in the conversation.\n - Boundary markers: The instructions do not specify the use of clear delimiters or instructions to the agent to disregard any embedded commands within the text being analyzed.\n
- Capability inventory: The skill uses the
Edittool to perform in-place modifications and usesStructured Interactionfor workflow control.\n - Sanitization: There is no documented process for sanitizing or filtering input text before it is analyzed for linguistic patterns.
Audit Metadata