sn-report-format-discovery

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No override commands or safety bypass patterns were detected. The instructions focus on structured data extraction and adherence to high-quality sourcing standards.
  • [DATA_EXFILTRATION]: No network exfiltration patterns, hardcoded credentials, or access to sensitive local files (like SSH keys or environment variables) were found. The skill operates on provided user requests and search tool outputs.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain instructions to download, install, or execute external scripts or packages.
  • [OBFUSCATION]: No Base64 encoding, zero-width characters, or other techniques to hide malicious intent were identified in the markdown content.
  • [DYNAMIC_EXECUTION]: The skill does not use runtime code evaluation (like eval/exec) or dynamic command construction that could lead to code injection.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external information from search results and user-provided request files. While this creates an inherent attack surface where external content could attempt to influence the agent, the skill includes explicit instructions for quality control, sourcing from authoritative domains (e.g., EQUATOR, NLM, APA), and validating credibility, which significantly mitigates this risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 09:37 AM