Gap Analysis

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No evidence of malicious behavior, prompt injection, or security guideline bypasses was found within the skill's instructions or metadata.\n- [PROMPT_INJECTION]: The skill processes untrusted external data (research papers), which presents an indirect prompt injection surface.\n- Ingestion points: PDF documents retrieved from local directories via Glob or from Zotero collections via MCP tools.\n- Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are applied to the text extracted from the papers.\n- Capability inventory: Includes file system access (Glob), Zotero collection management (zotero_get_collections), and the invocation of a specialized paper-reader sub-agent.\n- Sanitization: No explicit sanitization or validation of the paper content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 07:28 AM
Security Audit — agent-trust-hub — Gap Analysis