academic-pipeline

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes external tools such as Pandoc and tectonic (LaTeX compiler) to convert documents between formats (Markdown, DOCX, LaTeX, PDF). This is a core part of its intended functionality for academic document generation.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to verify academic citations and data. It uses the Semantic Scholar API and general WebSearch to cross-reference claims against the scientific literature. These operations are directed at trusted academic databases and well-known services.
  • [DATA_EXPOSURE]: The skill handles user-supplied academic papers and research data. While this is a sensitive data class, the skill includes explicit security measures, such as 'consent gates' that require user permission before uploading any dialogue or data to external models for cross-verification. It also defines private fields for abstracts and notes to protect user intellectual property.
  • [INDIRECT_PROMPT_INJECTION]: As an orchestrator that processes external academic drafts, the skill is theoretically susceptible to indirect prompt injection within the ingested papers. However, it implements a robust 'Integrity Verification Agent' and an 'AI Research Failure Mode Checklist' specifically designed to detect and block malicious content, hallucinations, or structural anomalies in the input data.
  • [PROMPT_INJECTION]: The skill uses 'Iron Rules' to enforce safety protocols and prevent the AI from skipping mandatory integrity checks. These internal constraints act as a defense against potential instructions within user data that might attempt to bypass safety guidelines.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 03:56 AM
Security Audit — agent-trust-hub — academic-pipeline