bias-assessor
Pass
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [Indirect Prompt Injection] (LOW): The skill is designed to process untrusted data from an external CSV file, creating a surface for indirect prompt injection.
- Ingestion points:
papers/extraction_table.csv(referenced in the Workflow section ofSKILL.md). - Boundary markers: Absent. The instructions do not define delimiters or provide specific warnings for the agent to ignore instructions embedded within the CSV fields.
- Capability inventory: None. The skill contains only markdown instructions and no executable scripts or command-line operations.
- Sanitization: Absent. There are no instructions for validating or sanitizing the content of the CSV before processing.
- [No Code] (SAFE): The skill contains no executable scripts (e.g., Python, Bash, Node.js), which significantly reduces the risk of malicious payload execution or system compromise.
Audit Metadata