ArXiv
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using
curlto send POST requests to a local notification service athttp://localhost:31337/notifyandechoto append execution metadata to a local JSONL file located at~/.claude/LIFEOS/MEMORY/SKILLS/execution.jsonl. - [EXTERNAL_DOWNLOADS]: The skill fetches paper metadata and AI-generated summaries from well-known academic services, specifically
export.arxiv.organdalphaxiv.org. These are established research platforms used as the primary data source for the skill's functionality. - [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted text from external sources.
- Ingestion points: Academic abstracts and AI-generated paper overviews are fetched from
export.arxiv.organdalphaxiv.orgin all workflows (Latest, Paper, Search). - Boundary markers: Absent; the instructions do not provide delimiters or specific warnings to the agent to ignore instructions that might be embedded within the fetched paper titles, abstracts, or summaries.
- Capability inventory: The agent possesses capabilities to execute shell commands (via
curlandecho) and read/write to specific local directories under~/.claude/. - Sanitization: Absent; the skill relies on simple text parsing of XML and Markdown content without explicit filtering or sanitization of potential injection strings.
Audit Metadata