literature-review

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run to execute git config user.email to retrieve a contact email address for use in 'polite pool' API headers. This is a standard practice for scholarly data tools to identify themselves to registries like Crossref and doi.org.
  • [EXTERNAL_DOWNLOADS]: The skill fetches publication metadata, citation graphs, and resolution status from well-known scholarly services including api.crossref.org, api.openalex.org, and doi.org. These are reputable scientific resources and their use is consistent with the skill's stated purpose.
  • [PROMPT_INJECTION]: As a literature review tool, the skill ingests third-party data (titles, abstracts, and author names) which constitutes an indirect prompt injection surface. The skill mitigates this through explicit instructions for evidence-based synthesis and a deterministic 'style pass' function in kernel.py that lints the agent's draft for process-oriented narration and poor citation practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 10:23 PM
Security Audit — agent-trust-hub — literature-review