ccf-rebuttal-writer

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and parse reviewer comments, which constitutes an untrusted data ingestion surface. However, the risk is assessed as safe because the skill has no dangerous capabilities such as network access, system command execution, or file writing that could be triggered by an injection. Evidence: Ingestion occurs in SKILL.md Step 2, where comments are parsed into issue groups. There are no boundary markers or sanitization mentioned, but the capability inventory is limited to text generation.
  • [SAFE]: The skill consists of LaTeX templates and instructional markdown focused exclusively on academic writing tasks. No obfuscation, hardcoded credentials, or remote code execution patterns were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 08:26 AM
Security Audit — agent-trust-hub — ccf-rebuttal-writer