investigate

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from research papers and web searches, creating a surface for indirect prompt injection.
  • Ingestion points: The skill reads content from reaper-workspace/papers/ and results from the arxiv.py and iacr.py scripts.
  • Boundary markers: There are no explicit delimiters or instructions to ignore commands found within external data.
  • Capability inventory: The skill can write to the local filesystem (investigation logs and results) and perform network searches.
  • Sanitization: No sanitization or validation logic is specified for ingested paper content.
  • [EXTERNAL_DOWNLOADS]: Fetches research papers from well-known scientific repositories including arXiv and IACR.
  • [COMMAND_EXECUTION]: Executes local search scripts arxiv.py and iacr.py to facilitate literature review.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 AM
Security Audit — agent-trust-hub — investigate