literature-triage-matrix

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [PROMPT_INJECTION]: The compatibility field in SKILL.md contains a self-referential safety claim ("security scan: SAFE"), which is a pattern designed to influence the agent's or analyzer's safety protocols.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources, which could contain malicious instructions.
  • Ingestion points: Manual paper lists provided in chat, Obsidian markdown notes in raw/, and Zotero metadata via local API.
  • Boundary markers: Absent; there are no instructions to the agent to ignore or delimit instructions found within the research content.
  • Capability inventory: The skill performs file read and write operations to the .research/ and raw/ directories.
  • Sanitization: Absent; the skill does not mention any validation or escaping of external content before processing.
  • [METADATA_POISONING]: The compatibility field contains unverifiable claims ("Verified loaded by NousResearch", "security scan: SAFE") intended to mislead users or scanners regarding the skill's security verification.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 07:41 AM
Security Audit — agent-trust-hub — literature-triage-matrix