academic-paper

Warn

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The visualization_agent generates Python (matplotlib/seaborn) or R (ggplot2) code based on quantitative study findings and is explicitly instructed in its internal workflow to execute this code to render and verify figures.
  • [PROMPT_INJECTION]: The skill features a large ingestion surface for untrusted external data, including literature abstracts, "unstructured reviewer comments" parsed by the revision_coach_agent, and user-provided past papers used for style calibration in the intake_agent.
  • [COMMAND_EXECUTION]: Reference guides and agent instructions (e.g., formatter_agent.md, latex_template_reference.md) provide the user with shell command templates for document conversion and processing using Pandoc, XeLaTeX, and Tectonic on the local system.
  • [REMOTE_CODE_EXECUTION]: The pipeline utilizes hidden HTML comments (e.g., <!--ref:slug-->, <!--anchor:kind:value-->) containing percent-encoded metadata to drive internal logic gates and verification steps during the drafting and formatting phases.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 18, 2026, 08:03 AM
Security Audit — agent-trust-hub — academic-paper