paper-writing-memory-manager

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process data from external draft files while possessing file-writing and shell-execution capabilities.
  • Ingestion points: The skill reads target draft files (e.g., .tex, .md) and project-level memory files within the paper directory.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded commands are specified when reading external draft content.
  • Capability inventory: The skill has access to the Read, Write, Edit, Bash, and Glob tools.
  • Sanitization: The skill does not describe any sanitization or validation logic for the content it processes from the paper directory.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 06:13 AM