literature-close-read

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs standard text processing and summarization tasks based on provided Markdown files. All operations are local and focus on data extraction from academic papers.
  • [EXTERNAL_DOWNLOADS]: The skill mentions an external tool pdf-extract and references a GitHub repository under the author's name (aipoch). These are consistent with the vendor's own tools and do not represent a security risk.
  • [COMMAND_EXECUTION]: The skill provides example commands for using pdf-extract and standard filesystem operations (mkdir). These are documented as user-driven or orchestration-driven steps rather than automated background executions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (PDF-to-Markdown conversions). However, it includes explicit boundary instructions ('summarize only what is explicitly present', 'no speculation', 'do not add assumptions') to mitigate the risk of the agent following instructions embedded within the paper text.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 12:36 PM
Security Audit — agent-trust-hub — literature-close-read