citation-management
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the
Bashtool to execute local Python scripts (scripts/*.py) for searching databases, converting identifiers, and formatting BibTeX files. These operations are consistent with the skill's stated purpose. - [EXTERNAL_DOWNLOADS]: The skill documentation describes fetching academic metadata from well-known and trusted services including PubMed (NCBI), CrossRef, arXiv, and Google Scholar. These interactions are standard for citation management workflows.
- [DATA_EXPOSURE]: The skill processes academic identifiers (DOIs, PMIDs) and metadata. It does not access sensitive system files, environment variables, or private credentials.
- [SAFE]: Analysis of the skill instructions and references reveals no evidence of prompt injection, obfuscation, privilege escalation, or persistence mechanisms. The use-case is legitimate and follows standard research practices.
Audit Metadata