paper-workflow-orchestrator

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script quickstart_run.py and instructions in SKILL.md utilize subprocess.run and shell commands to execute various Python scripts. These are internal orchestration scripts (e.g., preflight_check.py, workflow_guard.py) located within the skill's own directory structure used to manage the paper generation workflow.
  • [DYNAMIC_EXECUTION]: The skill's primary purpose involves the agent generating mathematical modeling code (e.g., q1_model.py) and executing it. The system includes a persistence layer (run_manifest.json) that records SHA-256 hashes of scripts and outputs to ensure results are derived from the intended code and to detect subsequent modifications.
  • [OBFUSCATION]: The preflight_check.py script uses importlib.import_module to dynamically verify the presence of optional library dependencies (such as pypdf, pandas, and openpyxl). This is a standard utility pattern for feature detection based on the types of user-provided input files.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the problem_files/ directory (including PDF, DOCX, and Excel files). This represents a vulnerability surface where maliciously crafted contest documents could attempt to influence the agent's logic during the subsequent analysis and code generation phases.
  • Ingestion points: Files in problem_files/ are read by scripts/preflight_check.py.
  • Boundary markers: None explicitly implemented for content extraction.
  • Capability inventory: Subprocess execution in quickstart_run.py and agent-led code generation/execution in the modeling phase.
  • Sanitization: Preflight checks focus on structural integrity and character counts rather than content filtering for injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:58 PM