grant-proposal

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill uses a Bash script to search for and execute a local Python utility (extract_paper_style.py). The path to this utility is computed at runtime by searching the project structure and environment variables like ARIS_REPO. \n- [INDIRECT_PROMPT_INJECTION]: The skill processes research data and literature from external sources via WebSearch and WebFetch to inform the proposal drafting. Maliciously crafted content in these external sources could theoretically influence the agent's output. \n
  • Ingestion points: Research summaries, literature survey results, and funded project details retrieved from external grant databases and academic search engines. \n
  • Boundary markers: The skill lacks explicit delimiters or instructions to treat external research content as potentially untrusted data. \n
  • Capability inventory: The skill is permitted to use Bash(*), Write, and external LLM processing via mcp__codex__codex. \n
  • Sanitization: No specific sanitization or filtering logic is described for the external content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:09 PM
Security Audit — agent-trust-hub — grant-proposal