academic-writing

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's protocol contains instructions for the agent to execute a shell command (uv run) on a script located at a variable local path (<literature-review-dir>/scripts/verify_citations.py) to validate scholarly citations.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted external data (user-supplied research drafts, literature notes, and academic prose), which represents an injection surface.
  • Ingestion points: User-provided research text and drafts processed during the anti-pattern detection and audit phases in SKILL.md.
  • Boundary markers: None identified; the protocol lacks delimiters or explicit instructions for the agent to ignore potentially malicious instructions embedded within the research data it analyzes.
  • Capability inventory: The skill uses Bash, Read, Grep, and Glob tools across its operations.
  • Sanitization: There is no evidence of input validation, escaping, or filtering applied to the external text before it is processed by these tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:58 PM
Security Audit — agent-trust-hub — academic-writing