academic-pipeline

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill is designed to execute numerous local Python scripts (e.g., 'scripts/ars_apply_revision_patch.py', 'scripts/verify_submission_package.py', 'scripts/check_literature_corpus_schema.py') to handle manuscript processing and validation. These scripts are expected components of the vendor's toolset but were not provided in the skill bundle for security auditing.
  • [PROMPT_INJECTION]: The skill processes untrusted external data in the form of academic papers and reference excerpts, which are interpolated into prompts for internal auditing agents. 1. Ingestion points: User-supplied manuscripts and retrieved literature excerpts. 2. Boundary markers: No explicit delimiters or 'ignore' instructions are implemented to isolate the processed document content. 3. Capability inventory: The agent has the ability to write to the file system, execute scripts, and perform web searches. 4. Sanitization: There is no evidence of content sanitization to prevent the agent from executing instructions embedded in academic texts.
  • [DATA_EXFILTRATION]: The skill includes an optional cross-model verification feature that sends manuscript content to external LLM providers. This is managed through a mandatory user consent gate that identifies the provider and content class before any data is sent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 08:03 AM
Security Audit — agent-trust-hub — academic-pipeline