kill-argument

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external LaTeX, BibTeX, and PDF files which could contain malicious instructions designed to subvert the agent's behavior.
  • Ingestion points: The skill inventories and reads all .tex and .bib files, as well as PDFs, within a user-specified directory defined by $ARGUMENTS (Workflow Steps 1 and 2).
  • Boundary markers: The prompt templates provided to the external mcp__codex__codex tool in Steps 2 and 3 lack explicit delimiters or instructions to ignore embedded prompts within the ingested research files.
  • Capability inventory: The skill has access to Bash(*), Write, and Edit, enabling the agent to execute shell commands and modify local files based on the review outcome.
  • Sanitization: No sanitization, validation, or filtering of the file contents is performed before the data is passed to the reviewer models or processed by shell tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:08 PM
Security Audit — agent-trust-hub — kill-argument