paper-relevance-filter
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes paper titles and abstracts fetched from external sources such as bioRxiv, medRxiv, and PubMed. This input represents a potential surface for indirect prompt injection where malicious instructions embedded in a paper's abstract could attempt to manipulate the relevance scoring or influence the agent's downstream behavior.
- Ingestion points: The
paperslist input parameter described in Step 1 ofSKILL.mdwhich contains external paper records. - Boundary markers: The instructions do not define explicit delimiters or 'ignore' instructions to wrap the external paper content during processing.
- Capability inventory: The skill's functionality is limited to calculating scores and returning a JSON object. It contains no subprocess calls, file-write operations, or network exfiltration capabilities.
- Sanitization: No specific sanitization or filtering logic is mentioned for the text content of the abstracts or titles before they are evaluated against the criteria.
Audit Metadata