academic-paper
Warn
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
visualization_agentgenerates Python (matplotlib/seaborn) or R (ggplot2) code based on quantitative study findings and is explicitly instructed in its internal workflow to execute this code to render and verify figures. - [PROMPT_INJECTION]: The skill features a large ingestion surface for untrusted external data, including literature abstracts, "unstructured reviewer comments" parsed by the
revision_coach_agent, and user-provided past papers used for style calibration in theintake_agent. - [COMMAND_EXECUTION]: Reference guides and agent instructions (e.g.,
formatter_agent.md,latex_template_reference.md) provide the user with shell command templates for document conversion and processing using Pandoc, XeLaTeX, and Tectonic on the local system. - [REMOTE_CODE_EXECUTION]: The pipeline utilizes hidden HTML comments (e.g.,
<!--ref:slug-->,<!--anchor:kind:value-->) containing percent-encoded metadata to drive internal logic gates and verification steps during the drafting and formatting phases.
Audit Metadata