seven-pass-review
Pass
Audited by Gen Agent Trust Hub on Apr 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute the
pdftotextutility on manuscript files supplied by the user during the pre-flight phase. - [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes untrusted content from manuscripts and passes it to sub-agents with broad tool access. \n
- Ingestion points: External manuscript file contents (Phase 0, Phase 1). \n
- Boundary markers: None present in the prompts to differentiate manuscript text from reviewer instructions. \n
- Capability inventory: Access to
Bash,Task(agent spawning), andWritetools across all lens reviewers. \n - Sanitization: No sanitization, escaping, or validation of the manuscript content is performed prior to analysis.
Audit Metadata