paper-workflow-orchestrator
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONOBFUSCATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script
quickstart_run.pyand instructions inSKILL.mdutilizesubprocess.runand shell commands to execute various Python scripts. These are internal orchestration scripts (e.g.,preflight_check.py,workflow_guard.py) located within the skill's own directory structure used to manage the paper generation workflow. - [DYNAMIC_EXECUTION]: The skill's primary purpose involves the agent generating mathematical modeling code (e.g.,
q1_model.py) and executing it. The system includes a persistence layer (run_manifest.json) that records SHA-256 hashes of scripts and outputs to ensure results are derived from the intended code and to detect subsequent modifications. - [OBFUSCATION]: The
preflight_check.pyscript usesimportlib.import_moduleto dynamically verify the presence of optional library dependencies (such aspypdf,pandas, andopenpyxl). This is a standard utility pattern for feature detection based on the types of user-provided input files. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the
problem_files/directory (including PDF, DOCX, and Excel files). This represents a vulnerability surface where maliciously crafted contest documents could attempt to influence the agent's logic during the subsequent analysis and code generation phases. - Ingestion points: Files in
problem_files/are read byscripts/preflight_check.py. - Boundary markers: None explicitly implemented for content extraction.
- Capability inventory: Subprocess execution in
quickstart_run.pyand agent-led code generation/execution in the modeling phase. - Sanitization: Preflight checks focus on structural integrity and character counts rather than content filtering for injection patterns.
Audit Metadata