semantic-scholar-deep
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The Python scripts (
ss_client.pyandcitation_graph.py) rely exclusively on Python standard libraries (urllib,json,argparse). By avoiding external package dependencies likerequests, the skill minimizes its supply chain attack surface. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize external academic data (titles, abstracts, and passages). While this presents a potential injection surface, the subagent instructions provide explicit directives to synthesize and rank results rather than passing raw API responses into the main conversation, which effectively mitigates the risk.
- [CREDENTIALS_SAFE]: The skill correctly handles API authentication by retrieving the
SEMANTIC_SCHOLAR_API_KEYfrom environment variables. No hardcoded credentials or unsafe storage mechanisms were detected. - [COMMAND_EXECUTION]: The skill utilizes local Python scripts for API interaction and citation graph traversal. These scripts are executed via standard Bash calls with properly sanitized arguments. There is no evidence of unsafe dynamic execution or remote script downloading and execution.
- [DATA_EXFILTRATION]: Network activity is restricted to the official Semantic Scholar API endpoints (
api.semanticscholar.org) and the designated Exa MCP discovery tool. No unauthorized or suspicious data exfiltration patterns were identified.
Audit Metadata