multi-source-investigation

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes shell commands using uv run to execute scripts located in a separate skill's directory. Specifically, it calls openalex_cli.py, europepmc_api.py, and read_paper.py located within the literature-review-dir.
  • [DYNAMIC_EXECUTION]: The skill executes scripts from a computed or placeholder path (<literature-review-dir>), indicating a functional dependency on the file structure of another skill.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill ingests untrusted data from the open web, news sites, and social media platforms using the WebSearch and WebFetch tools.
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters (e.g., XML tags or triple backticks) to isolate external content from the agent's internal reasoning context.
  • Capability inventory: The skill has access to the Bash tool and performs script execution via uv run, which could be targeted by instructions embedded in malicious research sources.
  • Sanitization: There are no instructions for sanitizing or validating the content retrieved from external sources before it is processed or used to generate investigative reports.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:29 PM
Security Audit — agent-trust-hub — multi-source-investigation