research-refine-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external and potentially untrusted data, creating a surface for indirect prompt injection attacks.
  • Ingestion points: The skill ingests user input via the $ARGUMENTS variable and reads existing files such as refine-logs/FINAL_PROPOSAL.md and refine-logs/REVIEW_SUMMARY.md (found in SKILL.md).
  • Boundary markers: The instructions lack explicit delimiters or "ignore embedded instructions" warnings for the content being processed.
  • Capability inventory: The skill utilizes powerful capabilities including Bash(*), Write, Edit, WebSearch, and WebFetch (found in YAML frontmatter).
  • Sanitization: No sanitization or validation protocols are defined to filter instructions from ingested data before they are interpreted by the agent.
  • [COMMAND_EXECUTION]: The skill instructs the agent to use shell commands to handle file operations, specifically as a silent fallback mechanism.
  • Evidence: In SKILL.md, a rule under "Key Rules" directs the agent to immediately retry failed file writes using Bash with cat << 'EOF' > file without requesting user permission.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:07 PM
Security Audit — agent-trust-hub — research-refine-pipeline