comm-lit-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from multiple sources which provides a surface for instructions embedded in data to override agent behavior.
- Ingestion points: The skill retrieves data via
WebSearch,WebFetch, and by reading the content of PDF files found in local directories (papers/,literature/), as well as user notes fromzoteroandobsidianMCPs. - Boundary markers: The instructions do not define any delimiters or explicit 'ignore embedded instructions' warnings for the data retrieved from external web pages or PDFs.
- Capability inventory: The agent is granted powerful capabilities including
Bash(*),Write,WebSearch, andWebFetch, which could be abused if the agent is manipulated by injected content. - Sanitization: There is no mention of sanitizing, escaping, or validating the text content extracted from papers or web results before it is incorporated into the synthesis process.
Audit Metadata