submission-disclosures
Pass
Audited by Gen Agent Trust Hub on Jun 14, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted data from external journal websites via
WebFetchto verify policies. This represents a potential surface for indirect prompt injection. - Ingestion points: Phase 1 uses
WebFetchon URLs found viaWebSearchfor journal policies. - Boundary markers: None explicitly specified for the fetched content.
- Capability inventory:
Read,Grep,Glob,Write,WebSearch, andWebFetchas defined in the skill's frontmatter. - Sanitization: None specified for the external content before drafting statements.
- [EXTERNAL_DOWNLOADS]: The skill performs web searches and fetches to retrieve up-to-date journal submission guidelines. This functionality is essential for its stated purpose and targets legitimate academic publishing resources.
Audit Metadata