paper-claim-audit
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted content from research paper files (.tex) and raw experiment result files (.json, .csv, .yaml) to generate an audit report.
- Ingestion points: Step 1 describes the collection of paper .tex files and various raw result formats (JSON, CSV, TSV) to be analyzed by the fresh reviewer model.
- Boundary markers: The system prompt in Step 2 instructs the reviewer model to maintain 'ZERO prior context' and follow a strict quantitative audit protocol, which acts as a logical boundary to reduce accidental obedience to embedded text, though it is not a formal security sandbox.
- Capability inventory: The skill has access to
Write,Edit, andBashtools. While used here for writing report artifacts and hashing files, these tools represent a capability surface that could be targeted if a reviewer model is influenced by malicious instructions hidden in the paper text. - Sanitization: There is no evidence of sanitization or escaping of the LaTeX content or raw data values before they are passed to the reviewer model for analysis.
Audit Metadata