aminer-pdf-citation-verifier

Pass

Audited by Gen Agent Trust Hub on Jul 22, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes external PDF files and API responses, which introduces a surface for indirect prompt injection. Malicious content within a PDF or a compromised API response could attempt to influence the agent's behavior. However, the risk is minimized as the skill only performs network requests to verified vendor domains and does not possess high-privilege capabilities.
  • [DATA_EXFILTRATION]: The skill transmits user-provided PDF content to the AMiner service (datacenter.aminer.cn) for analysis. This data transfer is the intended primary function of the skill and is clearly disclosed in the documentation.
  • [COMMAND_EXECUTION]: The skill utilizes a Python script to interact with the AMiner API. The script uses the requests library for HTTP communication and does not exhibit any patterns of arbitrary command execution or unsafe system calls.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 22, 2026, 03:07 AM
Security Audit — agent-trust-hub — aminer-pdf-citation-verifier