write-paper

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local workspace to generate technical reports, which could allow malicious content in source files to influence the agent's actions or the generated output.\n
  • Ingestion points: Reads content from reaper-workspace/notes/current-understanding.md, results.md, problem-statement.md, ideas.md, literature.md, and investigations/*/analysis.md as defined in SKILL.md.\n
  • Boundary markers: No explicit instructions are provided to the agent to ignore or delimit embedded instructions within the ingested files.\n
  • Capability inventory: The skill performs file writes to create the LaTeX project and shell command execution via make and latexmk (SKILL.md).\n
  • Sanitization: The skill only specifies basic escaping of LaTeX reserved characters in prose, paths, and bibliography fields, which does not prevent all forms of instruction injection.\n- [COMMAND_EXECUTION]: The skill triggers the execution of system commands based on generated build configurations.\n
  • Evidence: Instructions in SKILL.md mandate creating a Makefile and running make to compile the LaTeX project.\n- [DYNAMIC_EXECUTION]: The skill generates an executable build script (Makefile) at runtime and triggers its execution.\n
  • Evidence: Step 4 of SKILL.md defines the content of the Makefile and step 6 commands the agent to execute it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 AM
Security Audit — agent-trust-hub — write-paper