research-synthesis

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses uv run to execute scripts from a variable location (<literature-review-dir>). Dynamic execution from non-static paths is a medium-risk configuration as it depends on computed environment paths.\n- [COMMAND_EXECUTION]: The skill provides explicit instructions to execute CLI tools like openalex_cli.py and search_arxiv.py via the Bash tool to retrieve scholarly data.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests fragmented findings from academic sources which are untrusted external inputs.\n
  • Ingestion points: Scholarly papers and metadata from OpenAlex, Europe PMC, and arXiv fetched in SKILL.md.\n
  • Boundary markers: No delimiters or instructions to ignore embedded prompts are provided for the processed data.\n
  • Capability inventory: The skill has access to sensitive tools including Bash, WebSearch, WebFetch, Read, Grep, and Glob.\n
  • Sanitization: No validation or sanitization is performed on the ingested research content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 05:28 PM
Security Audit — agent-trust-hub — research-synthesis