research-expert
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data such as citation metadata and study parameters, creating a vulnerability surface.
- Ingestion points: Data enters through the
add_citationandStudyclass constructors inSKILL.md. - Boundary markers: No delimiters are present to separate data from instructions.
- Capability inventory: The agent can use
WriteandEdittools to persist this data. - Sanitization: No input validation or escaping is implemented.
Audit Metadata