bib-doi-toggle

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified.
  • Ingestion points: The skill reads content from main.tex and bibliography (.bib) files to locate package options and verify citation keys.
  • Boundary markers: Absent; the skill does not wrap the ingested LaTeX or BibTeX content in delimiters or include instructions to ignore embedded instructions.
  • Capability inventory: The skill is designed to modify the main.tex file to update biblatex package options.
  • Sanitization: Absent; the skill performs pattern matching and replacement on file content without specific escaping or validation of external input.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:28 AM
Security Audit — agent-trust-hub — bib-doi-toggle