systematic-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is configured to execute local shell scripts and Python scripts as part of its setup and operational flow.
  • Evidence: bash <plugin-root>/scripts/setup.sh is invoked during the prerequisite phase.
  • Evidence: Multiple instances of uv run <literature-review-dir>/scripts/X.py are used to interface with research databases and process data.
  • [DYNAMIC_EXECUTION]: The skill assembles and executes shell commands that incorporate dynamic environment variables and user-defined paths.
  • Evidence: Command strings are constructed using variables like $WS and ${slug}, such as uv run <literature-review-dir>/scripts/build_corpus.py --output "$WS/corpus.json".
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external scientific databases and web sources, which could potentially contain malicious instructions designed to influence the agent's behavior during synthesis.
  • Ingestion points: Data is retrieved from OpenAlex, Europe PMC, arXiv, and general web searches via WebSearch and WebFetch tools in the SKILL.md file.
  • Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded commands within the retrieved research papers or abstracts.
  • Capability inventory: The agent has access to Bash (command execution), WebFetch (network operations), and file system tools (Read, Grep, Glob).
  • Sanitization: There is no mention of sanitization, filtering, or validation of the external text content before it is processed for extraction or synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:29 PM
Security Audit — agent-trust-hub — systematic-review