ccf-paper-writer

Fail

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: CRITICALPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses research papers as style references. Several files, such as references/exemplars/papers/iclr-2025-safety-alignment.md, contain text describing various 'jailbreak' and 'DAN' prompts as part of their scientific discussion on AI safety. This represents an indirect prompt injection surface where the agent processes data containing potentially disruptive patterns, although the skill's core instructions explicitly forbid copying such content.
  • [EXTERNAL_DOWNLOADS]: Multiple URLs for academic venues and paper repositories (e.g., arxiv.org, aaai.org, coling2026.org) are referenced for retrieving citations and venue guidelines. These are established academic services and are documented neutrally as they are essential to the skill's primary function.
  • [COMMAND_EXECUTION]: The skill includes a Python utility scripts/convert_pdf_to_card.py for processing PDF documents into the internal 'exemplar card' format. The script uses standard libraries for text extraction and is a benign support tool for the skill's maintainers.
  • [DATA_EXFILTRATION]: The citation management process described in references/citation-workflow.md involves querying external literature databases. While this involves sending paper metadata to third-party services like DBLP or Semantic Scholar, it is a transparent part of the research workflow and does not involve sensitive user data.
Recommendations
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 13, 2026, 08:26 AM
Security Audit — agent-trust-hub — ccf-paper-writer