comm-lit-review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data from multiple sources which provides a surface for instructions embedded in data to override agent behavior.
  • Ingestion points: The skill retrieves data via WebSearch, WebFetch, and by reading the content of PDF files found in local directories (papers/, literature/), as well as user notes from zotero and obsidian MCPs.
  • Boundary markers: The instructions do not define any delimiters or explicit 'ignore embedded instructions' warnings for the data retrieved from external web pages or PDFs.
  • Capability inventory: The agent is granted powerful capabilities including Bash(*), Write, WebSearch, and WebFetch, which could be abused if the agent is manipulated by injected content.
  • Sanitization: There is no mention of sanitizing, escaping, or validating the text content extracted from papers or web results before it is incorporated into the synthesis process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — comm-lit-review