resubmit-pipeline
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external, untrusted data from prior reviewer reports and manuscript files to drive its automated improvement logic, creating a surface for indirect prompt injection.\n- Ingestion points: The skill ingests external content from manuscript files (.tex, .bib) and reviewer reports provided via the
--review-corpusdirectory path specified in the SKILL.md arguments.\n- Boundary markers: The orchestration logic does not explicitly define or enforce boundary markers (e.g., XML tags or delimiters) to wrap the reviewer reports, nor does it provide explicit instructions to the agent to disregard potential embedded commands within that specific external data.\n- Capability inventory: The skill is grantedBash(*),Read,Write,Edit,Grep, andGlobtools, providing it with the ability to modify the local filesystem, execute shell commands for document compilation, and interact with the Overleaf API.\n- Sanitization: The skill implements a critical mitigation by auto-generating and enforcing anedit_whitelist.yaml. This whitelist restricts the agent's editing scope to specific files and explicitly forbids high-risk operations such as adding new citations, theorems, or numerical claims, thereby constraining the potential impact of an injection attack.
Audit Metadata