ccf-paper-writer
Fail
Audited by Gen Agent Trust Hub on Aug 13, 2026
Risk Level: CRITICALPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses research papers as style references. Several files, such as
references/exemplars/papers/iclr-2025-safety-alignment.md, contain text describing various 'jailbreak' and 'DAN' prompts as part of their scientific discussion on AI safety. This represents an indirect prompt injection surface where the agent processes data containing potentially disruptive patterns, although the skill's core instructions explicitly forbid copying such content. - [EXTERNAL_DOWNLOADS]: Multiple URLs for academic venues and paper repositories (e.g.,
arxiv.org,aaai.org,coling2026.org) are referenced for retrieving citations and venue guidelines. These are established academic services and are documented neutrally as they are essential to the skill's primary function. - [COMMAND_EXECUTION]: The skill includes a Python utility
scripts/convert_pdf_to_card.pyfor processing PDF documents into the internal 'exemplar card' format. The script uses standard libraries for text extraction and is a benign support tool for the skill's maintainers. - [DATA_EXFILTRATION]: The citation management process described in
references/citation-workflow.mdinvolves querying external literature databases. While this involves sending paper metadata to third-party services like DBLP or Semantic Scholar, it is a transparent part of the research workflow and does not involve sensitive user data.
Recommendations
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata