systematic-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill is configured to execute local shell scripts and Python scripts as part of its setup and operational flow.
- Evidence:
bash <plugin-root>/scripts/setup.shis invoked during the prerequisite phase. - Evidence: Multiple instances of
uv run <literature-review-dir>/scripts/X.pyare used to interface with research databases and process data. - [DYNAMIC_EXECUTION]: The skill assembles and executes shell commands that incorporate dynamic environment variables and user-defined paths.
- Evidence: Command strings are constructed using variables like
$WSand${slug}, such asuv run <literature-review-dir>/scripts/build_corpus.py --output "$WS/corpus.json". - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external scientific databases and web sources, which could potentially contain malicious instructions designed to influence the agent's behavior during synthesis.
- Ingestion points: Data is retrieved from OpenAlex, Europe PMC, arXiv, and general web searches via
WebSearchandWebFetchtools in theSKILL.mdfile. - Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded commands within the retrieved research papers or abstracts.
- Capability inventory: The agent has access to
Bash(command execution),WebFetch(network operations), and file system tools (Read,Grep,Glob). - Sanitization: There is no mention of sanitization, filtering, or validation of the external text content before it is processed for extraction or synthesis.
Audit Metadata