aer-literature
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted text from external academic databases and web searches to verify citation accuracy, creating a surface for indirect prompt injection.\n
- Ingestion points: Academic abstracts, titles, and metadata are fetched from sources like Crossref, OpenAlex, NBER, and SSRN as described in
SKILL.mdandreferences/citation-verification-protocol.md.\n - Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions when processing this fetched text.\n
- Capability inventory: The agent is directed to use web search and fetch tools to retrieve external content.\n
- Sanitization: No explicit sanitization or filtering of fetched text is described.\n- [EXTERNAL_DOWNLOADS]: The skill directs the agent to fetch bibliographic data from well-known academic services such as Crossref and OpenAlex. These interactions are legitimate and consistent with the skill's purpose.
Audit Metadata