test-research-code
Pass
Audited by Gen Agent Trust Hub on Jul 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: Detailed analysis shows no evidence of malicious intent. The 'repro_check.py' script performs read-only operations on a local directory and uses regular expressions to find structural signals. No credential harvesting, persistence mechanisms, or unauthorized privilege escalations were identified.
- [PROMPT_INJECTION]: The skill processes external data (research repositories), which is an indirect prompt injection surface. The ingestion points are the files within the user-specified code directory and the '.paper-memory' directory. Capabilities include writing scaffolding files (e.g., requirements.txt, test scripts). While no sanitization or specific boundary markers for repository data are documented, the skill's operations are limited to specific engineering tasks that mitigate the risk of harmful outcomes from malicious repository content.
Audit Metadata