aris-comm-lit-review

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection due to its core function of ingesting untrusted data from academic databases and local files for summarization and analysis.
  • Ingestion points: The workflow in SKILL.md specifies reading external web content from ieeexplore.ieee.org, sciencedirect.com, and dl.acm.org, as well as potentially untrusted local data from Zotero, Obsidian notes, and local papers/ folders.
  • Boundary markers: Absent. There are no instructions or delimiters provided to the agent to distinguish between its primary task and any malicious instructions that might be embedded in the retrieved text from papers or user-synced notes.
  • Capability inventory: The frontmatter allows the use of powerful tools including Bash(*), Write, and Agent, which could be exploited if a document contains a malicious injection that influences the agent's behavior.
  • Sanitization: Absent. Content is processed directly for fact extraction and synthesis without filtering or validation for potential commands or guideline overrides.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 01:42 AM
Security Audit — agent-trust-hub — aris-comm-lit-review