academic-writing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill's protocol contains instructions for the agent to execute a shell command (
uv run) on a script located at a variable local path (<literature-review-dir>/scripts/verify_citations.py) to validate scholarly citations. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (user-supplied research drafts, literature notes, and academic prose), which represents an injection surface.
- Ingestion points: User-provided research text and drafts processed during the anti-pattern detection and audit phases in
SKILL.md. - Boundary markers: None identified; the protocol lacks delimiters or explicit instructions for the agent to ignore potentially malicious instructions embedded within the research data it analyzes.
- Capability inventory: The skill uses
Bash,Read,Grep, andGlobtools across its operations. - Sanitization: There is no evidence of input validation, escaping, or filtering applied to the external text before it is processed by these tools.
Audit Metadata