aer-literature

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text from external academic databases and web searches to verify citation accuracy, creating a surface for indirect prompt injection.\n
  • Ingestion points: Academic abstracts, titles, and metadata are fetched from sources like Crossref, OpenAlex, NBER, and SSRN as described in SKILL.md and references/citation-verification-protocol.md.\n
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when processing this fetched text.\n
  • Capability inventory: The agent is directed to use web search and fetch tools to retrieve external content.\n
  • Sanitization: No explicit sanitization or filtering of fetched text is described.\n- [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch bibliographic data from well-known academic services such as Crossref and OpenAlex. These interactions are legitimate and consistent with the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 09:21 AM
Security Audit — agent-trust-hub — aer-literature