paper-read
Pass
Audited by Gen Agent Trust Hub on May 11, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted content from research papers (PDFs, arXiv URLs, or text) to guide its analysis and wiki ingestion logic.\n
- Ingestion points: SKILL.md Phase 1 (PDF file paths, arXiv URLs, and user-pasted text).\n
- Boundary markers: Absent. There are no instructions to use delimiters or ignore embedded instructions within the paper content.\n
- Capability inventory: The skill has access to Read, Write, Edit, Bash, WebFetch, and WebSearch tools, enabling it to modify wiki files and execute shell commands.\n
- Sanitization: Absent. Information extracted from papers is directly used to update topic and concept pages.\n- [COMMAND_EXECUTION]: The skill presents a surface for command injection in Phase 5 by interpolating paper-derived topics into shell commands (e.g., the 'mental-gym' tool command).\n- [EXTERNAL_DOWNLOADS]: The skill fetches research papers from arXiv.org, which is a well-known and trusted academic service.
Audit Metadata