physics-reproducibility-archive

Warn

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: MEDIUMINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests external research data and code files without explicit boundary markers or sanitization logic. \n
  • Ingestion points: The skill reads raw data, simulation input parameters, and source code files (SKILL.md, Step 1). \n
  • Boundary markers: The instructions do not define delimiters for external content. \n
  • Capability inventory: The skill has the capability to execute code for testing and build containers using Docker or Apptainer. \n
  • Sanitization: There is no mention of sanitizing or validating the content of the ingested files. \n- [COMMAND_EXECUTION]: The skill requires building and running containers (Docker/Apptainer) and executing research code to verify reproducibility (SKILL.md, Step 3). These operations execute shell commands based on the contents and configuration of the provided research repository. \n- [DYNAMIC_EXECUTION]: The instruction to "test that it runs" (SKILL.md, Step 2) and produce output on a fresh host (SKILL.md, Step 3) involves dynamic execution of the research code and its associated dependencies on the local system or within a container environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 7, 2026, 03:00 AM
Security Audit — agent-trust-hub — physics-reproducibility-archive