paper-writing
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external text inputs including user-defined narratives, research topics, and style reference sources (which can be remote HTTP/HTTPS URLs or arXiv IDs) to generate paper plans and LaTeX sections via LLM calls (
gpt-6-astrathrough Codex MCP). Adversarial content embedded in these inputs could manipulate the pipeline's behavior or outputs. - Ingestion points: Ingests user-supplied
$ARGUMENTS,NARRATIVE_REPORT.md, and external reference files passed to the--style-refoption. - Boundary markers: Absent; the system does not wrap or isolate ingested data with strict semantic boundaries or specific instruction-guarding prompts.
- Capability inventory: Involves local file modifications, execution of helper scripts (
extract_paper_style.py,verify_paper_audits.sh), document compilation (latexmk), and interacting with Codex MCP servers. - Sanitization: No input validation or sanitization is specified for raw narrative content or text retrieved from external style sources.
- [COMMAND_EXECUTION]: The workflow incorporates automated bash code blocks that execute local tools (
extract_paper_style.pyandverify_paper_audits.sh) discovered dynamically via repository path resolution mechanisms (.aris/installed-skills.txtor~/.aris/repo). Though these are designed to serve internal automation, executing binaries and scripts using computed paths is an operational capability that requires safe repository state assumptions.
Audit Metadata