review-literature

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an attack surface for indirect prompt injection because it ingests and processes untrusted data from external sources.
  • Ingestion points: Untrusted content enters the agent's context through web search results (Step 3), paper abstracts and metadata (Steps 2, 4, and 5), and the full text of downloaded PDF papers (Step 8).
  • Boundary markers: The skill utilizes structured output formats such as JSON objects for subagents and Markdown tables for reports, but it does not specify clear delimiters or "ignore instructions" warnings when processing the text extracted from external research papers.
  • Capability inventory: The skill is capable of writing multiple files to the local workspace (reaper-workspace/) and invoking downstream tools like analyze-paper and search-paper.
  • Sanitization: There is no evidence of sanitization, filtering, or validation steps to ensure that instructions hidden within academic papers (e.g., in metadata or body text) are not executed by the agent or the analysis skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 AM
Security Audit — agent-trust-hub — review-literature