experiment-story-writer

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The core instructions and reference materials are focused exclusively on scientific writing. The logic for mapping claims to evidence and structuring narrative prose is consistent with academic standards and contains no malicious directives or safety bypasses.
  • [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection due to its requirement to read and process external project files. 1. Ingestion points: The skill reads LaTeX source files (.tex), figures, tables, and experiment logs/reports from the project directory. 2. Boundary markers: There are no explicit instructions to use delimiters or ignore instructions within the ingested content. 3. Capability inventory: The skill is granted access to Read, Write, Edit, and Bash tools, allowing it to modify project files. 4. Sanitization: No procedures are defined for validating or sanitizing the content of ingested logs or reports.
  • [COMMAND_EXECUTION]: While the skill is allowed access to the Bash tool, its instructions limit its use to local file system navigation and asset management within the paper repository, which is appropriate for the intended use case.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 12:40 PM