phd-literature-review
Pass
Audited by Gen Agent Trust Hub on Apr 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Phase P8 utilizes a shell command to run a bundled Python script (
generate_docx.py). This script formats the synthesis results into a Word document following doctoral dissertation standards for margin and font styles.\n- [EXTERNAL_DOWNLOADS]: The skill retrieves academic data and research metadata from external scholarly search engines and publishers (e.g., Google Scholar, SAGE, Wiley, ScienceDirect, and CNKI) during the systematic literature search phase (Phase P2).\n- [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting untrusted data from academic search results in Phase P2. While the workflow includes verification steps, the synthesis of external scholarly content into writing and the passage of parameters to scripts represents a potential surface common to automated research agents.
Audit Metadata