survey-generator

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs to generate literature surveys, creating a pathway for indirect instructions to influence the agent.
  • Ingestion points: The agent uses WebFetch to read from a user-provided source_url (e.g., arXiv papers or GitHub repositories) as defined in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands when the fetched content is interpolated into the final LLM prompt in scripts/build-survey.js.
  • Capability inventory: The skill can write files to the local system (fs.writeFileSync), execute local scripts (execFileSync), and make network requests to LLM provider APIs.
  • Sanitization: The script performs basic sanitization for markdown table safety but does not filter the core content for potential prompt injection vectors.
  • [COMMAND_EXECUTION]: The scripts/build-survey.js file uses execFileSync to invoke a local utility script, wiki-cli.js, to index the generated survey artifacts.
  • [DYNAMIC_EXECUTION]: The script performs a dynamic require() of a local database library (dist/db/store.js) using a path constructed at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 10:20 AM
Security Audit — agent-trust-hub — survey-generator