Survey SOP
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill establishes a systematic workflow for ingesting and processing external research papers, creating a potential vector for indirect prompt injection.\n
- Ingestion points: The workflow relies on
library_searchto read paper content andmonitor_get_contextto scan external feeds or documents for synthesis.\n - Boundary markers: The SOP does not include instructions for using delimiters or explicit system-level isolation when the agent processes untrusted text from external papers.\n
- Capability inventory: The skill possesses the capability to write to the local workspace via
workspace_save, manage and link tasks viatask_createandtask_link, and update paper metadata vialibrary_update_paper.\n - Sanitization: The workflow lacks explicit validation or sanitization steps for content extracted from external sources before it is incorporated into syntheses or reports.
Audit Metadata