resubmit-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from prior reviewer reports and manuscript files to drive its automated improvement logic, creating a surface for indirect prompt injection.\n- Ingestion points: The skill ingests external content from manuscript files (.tex, .bib) and reviewer reports provided via the --review-corpus directory path specified in the SKILL.md arguments.\n- Boundary markers: The orchestration logic does not explicitly define or enforce boundary markers (e.g., XML tags or delimiters) to wrap the reviewer reports, nor does it provide explicit instructions to the agent to disregard potential embedded commands within that specific external data.\n- Capability inventory: The skill is granted Bash(*), Read, Write, Edit, Grep, and Glob tools, providing it with the ability to modify the local filesystem, execute shell commands for document compilation, and interact with the Overleaf API.\n- Sanitization: The skill implements a critical mitigation by auto-generating and enforcing an edit_whitelist.yaml. This whitelist restricts the agent's editing scope to specific files and explicitly forbids high-risk operations such as adding new citations, theorems, or numerical claims, thereby constraining the potential impact of an injection attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 02:42 PM
Security Audit — agent-trust-hub — resubmit-pipeline