alterlab-biorxiv

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
  • Ingestion points: The skill retrieves paper titles, abstracts, and metadata from the external bioRxiv API in scripts/biorxiv_search.py.
  • Boundary markers: Although search results are returned in structured JSON, the skill does not implement delimiters or specific instructions to the agent to prevent the interpretation of instructions that might be contained within academic abstracts.
  • Capability inventory: The scripts/biorxiv_search.py file contains capabilities for writing to the file system, including downloading PDF files and saving JSON search results.
  • Sanitization: There is no evidence of sanitization or filtering of the retrieved paper content to strip potentially malicious instructions before the data is presented to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 12:46 AM
Security Audit — agent-trust-hub — alterlab-biorxiv