grant-proposal
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is subject to indirect prompt injection due to its core function of analyzing untrusted research data.
- Ingestion points: Processes external data from
$ARGUMENTSand local project files includingIDEA_REPORT.md,publications.md, andAUTO_REVIEW.md. - Boundary markers: The skill does not define explicit delimiters or 'ignore-previous-instructions' wrappers for ingested text.
- Capability inventory: The agent has access to
Bash(*),Write, andWebFetch, which could be exploited following a successful injection. - Sanitization: No specific text sanitization is described, although the use of '🚦 Checkpoint' prompts effectively mitigates risk by requiring human-in-the-loop verification before major tasks.
- [EXTERNAL_DOWNLOADS]: Retrieves configuration and research landscape data from well-known academic services.
- Evidence: Automatically queries the KAKEN database (kaken.nii.ac.jp) and NSF Award Search (nsf.gov) using
WebSearchandWebFetchto verify research novelty and competition.
Audit Metadata