comm-lit-review-claude-single

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the $ARGUMENTS variable.
  • Ingestion points: User-provided research topics enter the agent context via the $ARGUMENTS placeholder in SKILL.md.
  • Boundary markers: There are no delimiters (e.g., XML tags, triple quotes) or explicit instructions to ignore embedded commands within the research topic input.
  • Capability inventory: The skill possesses significant capabilities, including local file system access (Read, Glob, Grep, Bash), web access (WebSearch, WebFetch), and access to personal data via Zotero and Obsidian MCP tools.
  • Sanitization: There is no evidence of input validation or escaping for the user-supplied arguments before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:51 PM
Security Audit — agent-trust-hub — comm-lit-review-claude-single