write-paper
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local workspace to generate technical reports, which could allow malicious content in source files to influence the agent's actions or the generated output.\n
- Ingestion points: Reads content from reaper-workspace/notes/current-understanding.md, results.md, problem-statement.md, ideas.md, literature.md, and investigations/*/analysis.md as defined in SKILL.md.\n
- Boundary markers: No explicit instructions are provided to the agent to ignore or delimit embedded instructions within the ingested files.\n
- Capability inventory: The skill performs file writes to create the LaTeX project and shell command execution via make and latexmk (SKILL.md).\n
- Sanitization: The skill only specifies basic escaping of LaTeX reserved characters in prose, paths, and bibliography fields, which does not prevent all forms of instruction injection.\n- [COMMAND_EXECUTION]: The skill triggers the execution of system commands based on generated build configurations.\n
- Evidence: Instructions in SKILL.md mandate creating a Makefile and running make to compile the LaTeX project.\n- [DYNAMIC_EXECUTION]: The skill generates an executable build script (Makefile) at runtime and triggers its execution.\n
- Evidence: Step 4 of SKILL.md defines the content of the Makefile and step 6 commands the agent to execute it.
Audit Metadata