paper-polish-workflow
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from user-provided paper drafts and PDF reference documents, creating a potential surface for instructions embedded within the text to influence agent behavior.
- Ingestion points: User-provided text, file paths, and PDF reference papers described in Step 1 of the workflow.
- Boundary markers: The instructions do not specify the use of delimiters or specific instructions to the agent to disregard commands within the processed text.
- Capability inventory: The skill utilizes the Read tool to ingest data and describes writing content to new files (
*_polished.md). - Sanitization: There are no explicit validation or sanitization steps mentioned for the content being processed.
Audit Metadata