paper-workbench

Warn

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/normalize_paper.py uses importlib.util to dynamically load scripts/xray_io.py at runtime. While the path is constructed relative to the script's location, dynamic loading of modules from computed paths is a significant technique that could be abused if the filesystem is compromised.
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process academic papers from external sources including arXiv, AlphaXiv, and user-provided PDFs. This data is untrusted and could contain adversarial instructions intended to bias the literature synthesis, review outlines, or strategic analysis produced by the agent.
  • Ingestion points: scripts/normalize_paper.py (fetching from URLs and parsing HTML/BibTeX) and scripts/xray_io.py (extracting text from local PDF and text files).
  • Boundary markers: The instructions in SKILL.md and reference modes do not explicitly define strict boundary markers or 'ignore' instructions when interpolating paper content into analysis prompts.
  • Capability inventory: The skill has access to Bash for running Python scripts and Write capabilities for persisting JSON artifacts to the local workspace.
  • Sanitization: The scripts perform basic text normalization and HTML unescaping, but lack specific sanitization logic to detect or neutralize prompt injection attempts within paper abstracts or full text.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 3, 2026, 05:04 AM