paper-write

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill performs outbound HTTP requests via curl and Python's urllib.request to non-whitelisted domains (dblp.org and doi.org) to fetch and validate paper citation data.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection vulnerability surface because it processes external, untrusted content.
  • Ingestion points: Reads text from PAPER_PLAN.md, NARRATIVE_REPORT.md, and external files or URLs provided via the — style-ref argument.
  • Boundary markers: Absent. The skill does not instruct the agent to enclose untrusted content within strict boundary tags or include specific warnings to disregard nested instructions.
  • Capability inventory: The skill maintains powerful capabilities including arbitrary shell execution via Bash(*) and file modification tools (Write, Edit).
  • Sanitization: Absent. There is no pre-processing or sanitization phase to strip potentially malicious syntax or instructions embedded within user-supplied text or draft repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — paper-write