ip-disclosure-triage

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted research documents which introduces an indirect prompt injection surface.\n
  • Ingestion points: The skill is designed to read external files such as paper drafts (論文案), presentation materials (発表資料), and research plans (研究計画).\n
  • Boundary markers: There are no explicit instructions or delimiters provided to isolate the content of these external documents from the agent's core instructions.\n
  • Capability inventory: The skill has access to shell execution via Bash, file system access through Write, and network access via WebSearch/WebFetch.\n
  • Sanitization: There are no described methods for sanitizing or validating the content extracted from the provided research materials.\n- [COMMAND_EXECUTION]: The skill utilizes a shell tool for administrative data organization tasks.\n
  • Evidence: The skill uses the Bash tool to format 期限表 (deadline tables), 関係者表 (stakeholder tables), and 資料一覧 (material lists).\n- [EXTERNAL_DOWNLOADS]: The skill performs network operations to retrieve and verify research-related metadata.\n
  • Evidence: The skill uses WebSearch and WebFetch to check 公開予定 (publication schedules), DOI, and 先行公開情報 (prior disclosure information).
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 03:37 AM
Security Audit — agent-trust-hub — ip-disclosure-triage