education-research-assistant

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from untrusted external sources including academic databases (RISS, DBpia, Google Scholar) and user-uploaded research files, creating a surface for indirect prompt injection. \n
  • Ingestion points: Academic databases (RISS, DBpia, Google Scholar, PubMed, IEEE Xplore, JSTOR) and project input files (_workspace/00_input.md). \n
  • Boundary markers: The workflow lacks explicit boundary markers or instructions to the LLM to ignore potentially malicious instructions within processed documents. \n
  • Capability inventory: The skill performs file system writes to a workspace directory and generates Python/R code for statistical analysis. \n
  • Sanitization: There is no evidence of sanitization or input validation for external data. \n- [DYNAMIC_EXECUTION]: The skill employs a dedicated role to generate Python and R code for statistical modeling. \n
  • Evidence: The reference/academic-paper.md file explicitly tasks the '통계 분석가' (Statistical Analyst) with generating code using 'statsmodels' and 'scipy' libraries.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:42 PM
Security Audit — agent-trust-hub — education-research-assistant