submission-disclosures

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted data from external journal websites via WebFetch to verify policies. This represents a potential surface for indirect prompt injection.
  • Ingestion points: Phase 1 uses WebFetch on URLs found via WebSearch for journal policies.
  • Boundary markers: None explicitly specified for the fetched content.
  • Capability inventory: Read, Grep, Glob, Write, WebSearch, and WebFetch as defined in the skill's frontmatter.
  • Sanitization: None specified for the external content before drafting statements.
  • [EXTERNAL_DOWNLOADS]: The skill performs web searches and fetches to retrieve up-to-date journal submission guidelines. This functionality is essential for its stated purpose and targets legitimate academic publishing resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 11:26 AM
Security Audit — agent-trust-hub — submission-disclosures