research-paper-writer
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data in the form of user-provided research materials, creating a potential surface for indirect prompt injection. However, because the skill lacks any active capabilities such as network access, file system modification, or command execution, the threat is effectively mitigated.
- Ingestion points: Research materials, datasets, and references provided by the user as described in SKILL.md.
- Boundary markers: The instructions do not define specific delimiters or warnings to ignore embedded instructions in the provided materials.
- Capability inventory: The skill is limited to text generation; the index.js file contains only a placeholder log statement.
- Sanitization: No specific validation or sanitization routines for the input data are identified.
Audit Metadata