grant-proposal-review

Pass

Audited by Gen Agent Trust Hub on May 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill's primary function involves reading and analyzing untrusted external content (research grant proposals).
  • Ingestion points: The skill ingests content from external files (PDF or text) using the Read tool as defined in the 'Required Inputs' section and 'Step 1'.
  • Boundary markers: The instructions lack explicit boundary markers or directives for the agent to treat the contents of the grant proposal as data rather than instructions.
  • Capability inventory: The skill has access to WebSearch, WebFetch, Write, and Bash tools, which could potentially be targeted by an attacker embedding instructions within a proposal document.
  • Sanitization: There is no evidence of content sanitization or validation of the input files before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
May 19, 2026, 07:54 AM
Security Audit — agent-trust-hub — grant-proposal-review