conference-cfp-submission
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from external conference 'Call for Papers' (CFP) pages and user-provided URLs, creating a surface for indirect prompt injection if an attacker-controlled page contains malicious instructions.
- Ingestion points: The skill instructs the agent to read external CFP pages and pasted content as part of the research process (Step 1 in SKILL.md).
- Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within external content.
- Capability inventory: The skill performs text analysis and generates structured markdown documents based on ingested data.
- Sanitization: No explicit sanitization or filtering of external content is performed.
- [SAFE]: The skill references speakerline.io as a resource for researching accepted conference proposals, which is a common and legitimate practice in this domain.
- [SAFE]: The skill references other tools within the 'samber' vendor ecosystem for talk outlining and demo design, representing normal inter-skill functionality.
Audit Metadata