arxiv-categorical-ai
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is focused on academic research and meta-analysis. The included Python code serves as a template for data organization and does not perform any dangerous operations such as shell command execution, file system modification, or unauthorized network requests.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external academic papers (ArXiv). While this represents a theoretical surface for indirect prompt injection—where a researcher could embed malicious instructions in a paper's text—the risk is assessed as safe because the skill does not possess the capabilities to act on such instructions in a way that would compromise the host system.
- Ingestion points: Data extracted from academic papers into
PaperAnalysisobjects (skill.md). - Boundary markers: None explicitly defined in the logic snippets.
- Capability inventory: No subprocess calls, file-write operations, or network exfiltration patterns exist within the skill's logic.
- Sanitization: None present; the skill assumes the data processed is academic text content.
Audit Metadata