literature-review
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runto executegit config user.emailto retrieve a contact email address for use in 'polite pool' API headers. This is a standard practice for scholarly data tools to identify themselves to registries like Crossref and doi.org. - [EXTERNAL_DOWNLOADS]: The skill fetches publication metadata, citation graphs, and resolution status from well-known scholarly services including
api.crossref.org,api.openalex.org, anddoi.org. These are reputable scientific resources and their use is consistent with the skill's stated purpose. - [PROMPT_INJECTION]: As a literature review tool, the skill ingests third-party data (titles, abstracts, and author names) which constitutes an indirect prompt injection surface. The skill mitigates this through explicit instructions for evidence-based synthesis and a deterministic 'style pass' function in
kernel.pythat lints the agent's draft for process-oriented narration and poor citation practices.
Audit Metadata