literature-triage-matrix
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [PROMPT_INJECTION]: The
compatibilityfield inSKILL.mdcontains a self-referential safety claim ("security scan: SAFE"), which is a pattern designed to influence the agent's or analyzer's safety protocols. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, which could contain malicious instructions.
- Ingestion points: Manual paper lists provided in chat, Obsidian markdown notes in
raw/, and Zotero metadata via local API. - Boundary markers: Absent; there are no instructions to the agent to ignore or delimit instructions found within the research content.
- Capability inventory: The skill performs file read and write operations to the
.research/andraw/directories. - Sanitization: Absent; the skill does not mention any validation or escaping of external content before processing.
- [METADATA_POISONING]: The
compatibilityfield contains unverifiable claims ("Verified loaded by NousResearch", "security scan: SAFE") intended to mislead users or scanners regarding the skill's security verification.
Audit Metadata