citation-audit

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from LaTeX source files and BibTeX databases to perform its audit. This data is interpolated into prompts for a secondary LLM reviewer, creating a potential vector for indirect prompt injection where malicious instructions in a paper draft could influence the audit verdict.
  • Ingestion points: LaTeX files (.tex) and bibliography files (.bib) are read to extract citation context and metadata.
  • Boundary markers: The skill utilizes structured markdown headers (e.g., '## Bib entry') within the reviewer prompt to separate instructions from untrusted project data.
  • Capability inventory: The skill has access to tools for file modification (Edit/Write), document compilation (Bash/latexmk), and external data retrieval (WebSearch/WebFetch).
  • Sanitization: The workflow does not include explicit sanitization or filtering of the extracted manuscript text before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:52 PM
Security Audit — agent-trust-hub — citation-audit