academic-pipeline
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses instructional language like "IRON RULE" and "MANDATORY" to enforce internal workflows and academic standards. No evidence was found of attempts to bypass safety filters or override system instructions.
- [DATA_EXFILTRATION]: The skill handles sensitive academic materials (drafts, research notes) and uses "WebFetch" for literature retrieval. These actions are strictly within the scope of its stated research purpose. No evidence of unauthorized data transmission or hardcoded credentials was found.
- [COMMAND_EXECUTION]: The skill uses the "Bash" tool to execute local utility scripts (e.g., "scripts/ars_apply_revision_patch.py") and standard academic tools like "Pandoc" and "tectonic". These executions are well-defined within the orchestrator's logic and used for document processing.
- [REMOTE_CODE_EXECUTION]: No patterns of downloading and executing remote scripts (like "curl | bash") were identified. External interactions are limited to verified academic APIs and web search for source verification.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external research data, which is a potential surface for indirect injection. However, it incorporates specific "Anti-Hallucination" and "Pattern Protection" mandates, along with mandatory integrity verification stages (2.5 and 4.5), which act as significant mitigations.
- [OBFUSCATION]: Analysis found no signs of Base64, hex, or other encoding techniques used to hide malicious commands or URLs.
Audit Metadata