evidence-review
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill and its associated scripts do not exhibit malicious behavior, obfuscation, or unauthorized access to sensitive system resources.
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local Python script (scripts/check_review_package.py) that performs integrity checks on project directories and CSV files. This execution is confined to local project paths and does not involve network operations.
- [PROMPT_INJECTION]: The skill is designed to process user-supplied literature notes and evidence files. While this represents a potential surface for indirect prompt injection, the workflow explicitly instructs the agent to maintain evidence-controlled boundaries and verify claims against specific data statuses, which acts as a safeguard against malicious or accidental misinformation in source data.
Audit Metadata