survey-generator
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external URLs to generate literature surveys, creating a pathway for indirect instructions to influence the agent.
- Ingestion points: The agent uses
WebFetchto read from a user-providedsource_url(e.g., arXiv papers or GitHub repositories) as defined inSKILL.md. - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands when the fetched content is interpolated into the final LLM prompt in
scripts/build-survey.js. - Capability inventory: The skill can write files to the local system (
fs.writeFileSync), execute local scripts (execFileSync), and make network requests to LLM provider APIs. - Sanitization: The script performs basic sanitization for markdown table safety but does not filter the core content for potential prompt injection vectors.
- [COMMAND_EXECUTION]: The
scripts/build-survey.jsfile usesexecFileSyncto invoke a local utility script,wiki-cli.js, to index the generated survey artifacts. - [DYNAMIC_EXECUTION]: The script performs a dynamic
require()of a local database library (dist/db/store.js) using a path constructed at runtime.
Audit Metadata