ccf-paper-reviewer

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill incorporates a mandatory security check in 'references/desk-checks.md' specifically designed to identify prompt injection and hidden manipulation in manuscripts, instructing the agent to treat such content as data rather than instructions.- [SAFE]: Strict data exfiltration preventions are embedded in the workflow; 'SKILL.md' and 'references/review-workflow.md' mandate that external searches use 'public-safe' transformed queries and explicitly forbid pasting private manuscript text into web queries.- [COMMAND_EXECUTION]: To support formatting audits, the skill may run local build commands (e.g., make, latexmk) based on the provided repository's README or Makefile, which is a standard requirement for verifying LaTeX compilation.- [PROMPT_INJECTION]: The skill manages an indirect prompt injection surface through its processing of untrusted manuscripts. Ingestion points: Processes user-provided manuscripts in PDF, TeX, and Markdown formats across all review modes. Boundary markers: Utilizes 'references/desk-checks.md' to explicitly flag and ignore hidden instructions within manuscript text. Capability inventory: Includes shell-based build command execution for LaTeX audits in 'references/writing-review/latex-format-audit.md'. Sanitization: Employs 'public-safe' query transformations for related-work searches to ensure untrusted data does not influence network operations or leak private information.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 08:26 AM
Security Audit — agent-trust-hub — ccf-paper-reviewer