investigate
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from research papers and web searches, creating a surface for indirect prompt injection.
- Ingestion points: The skill reads content from
reaper-workspace/papers/and results from thearxiv.pyandiacr.pyscripts. - Boundary markers: There are no explicit delimiters or instructions to ignore commands found within external data.
- Capability inventory: The skill can write to the local filesystem (investigation logs and results) and perform network searches.
- Sanitization: No sanitization or validation logic is specified for ingested paper content.
- [EXTERNAL_DOWNLOADS]: Fetches research papers from well-known scientific repositories including arXiv and IACR.
- [COMMAND_EXECUTION]: Executes local search scripts
arxiv.pyandiacr.pyto facilitate literature review.
Audit Metadata