analyze-paper

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (academic papers) which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The skill accepts a <paper-path> argument and uses file tools to read and extract text from these external documents (SKILL.md, Step 1).
  • Boundary markers: The instructions do not define explicit delimiters or include warnings to the agent to ignore or disregard instructions embedded within the papers themselves.
  • Capability inventory: The skill possesses file reading (PDF/text extraction) and file writing capabilities (Step 3: Write Output) which could be misused if the agent obeys instructions found in the analyzed data.
  • Sanitization: There is no mention of sanitization, filtering, or validation of the extracted content before the agent processes it and writes findings to the output file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 AM
Security Audit — agent-trust-hub — analyze-paper