ccf-literature-searcher

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through its core search and report generation functionality.
  • Ingestion points: The skill retrieves content from external web searches and academic repositories such as DBLP, Semantic Scholar, and official proceedings pages (SKILL.md, references/search-and-scoring.md).
  • Boundary markers: The skill includes 'Invocation Controls' and 'private material safety' instructions intended to keep private user data out of search queries, but it lacks explicit delimiters or instructions to ignore embedded commands in the retrieved external paper content.
  • Capability inventory: The skill utilizes web search capabilities and file system access to create multi-file report folders (papers.md, papers.csv, search-notes.md).
  • Sanitization: No specific sanitization, escaping, or validation mechanisms are defined for content ingested from external sources before it is included in reports or processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 08:26 AM
Security Audit — agent-trust-hub — ccf-literature-searcher