citation-management

Pass

Audited by Gen Agent Trust Hub on Apr 6, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute local Python scripts (scripts/*.py) for searching databases, converting identifiers, and formatting BibTeX files. These operations are consistent with the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: The skill documentation describes fetching academic metadata from well-known and trusted services including PubMed (NCBI), CrossRef, arXiv, and Google Scholar. These interactions are standard for citation management workflows.
  • [DATA_EXPOSURE]: The skill processes academic identifiers (DOIs, PMIDs) and metadata. It does not access sensitive system files, environment variables, or private credentials.
  • [SAFE]: Analysis of the skill instructions and references reveals no evidence of prompt injection, obfuscation, privilege escalation, or persistence mechanisms. The use-case is legitimate and follows standard research practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 6, 2026, 11:29 PM
Security Audit — agent-trust-hub — citation-management