paper-write
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill performs outbound HTTP requests via
curland Python'surllib.requestto non-whitelisted domains (dblp.organddoi.org) to fetch and validate paper citation data. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface because it processes external, untrusted content.
- Ingestion points: Reads text from
PAPER_PLAN.md,NARRATIVE_REPORT.md, and external files or URLs provided via the— style-refargument. - Boundary markers: Absent. The skill does not instruct the agent to enclose untrusted content within strict boundary tags or include specific warnings to disregard nested instructions.
- Capability inventory: The skill maintains powerful capabilities including arbitrary shell execution via
Bash(*)and file modification tools (Write,Edit). - Sanitization: Absent. There is no pre-processing or sanitization phase to strip potentially malicious syntax or instructions embedded within user-supplied text or draft repositories.
Audit Metadata