Flagged by auditors
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe Academic Pipeline skill is a sophisticated orchestrator for end-to-end research workflows. It manages complex handoffs between specialized agents for research, writing, integrity verification, and peer review. The skill utilizes a series of local Python scripts and external tools (Pandoc, Tectonic) to process documents and maintain state. Security analysis identifies an inherent attack surface for Indirect Prompt Injection, as the skill ingests and processes user-supplied manuscripts and external reviewer feedback. However, the skill incorporates robust safety measures, including mandatory automated verification of all citations against ground-truth APIs and a structured review process. No malicious patterns, obfuscation, or unauthorized data operations were detected.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 3 issues
Runlayer
fail5/13 files flagged
ZeroLeaks
pass1 finding · Score: 86/100