skills/danielmiessler/lifeos/ArXiv/Gen Agent Trust Hub

ArXiv

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands using curl to send POST requests to a local notification service at http://localhost:31337/notify and echo to append execution metadata to a local JSONL file located at ~/.claude/LIFEOS/MEMORY/SKILLS/execution.jsonl.
  • [EXTERNAL_DOWNLOADS]: The skill fetches paper metadata and AI-generated summaries from well-known academic services, specifically export.arxiv.org and alphaxiv.org. These are established research platforms used as the primary data source for the skill's functionality.
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted text from external sources.
  • Ingestion points: Academic abstracts and AI-generated paper overviews are fetched from export.arxiv.org and alphaxiv.org in all workflows (Latest, Paper, Search).
  • Boundary markers: Absent; the instructions do not provide delimiters or specific warnings to the agent to ignore instructions that might be embedded within the fetched paper titles, abstracts, or summaries.
  • Capability inventory: The agent possesses capabilities to execute shell commands (via curl and echo) and read/write to specific local directories under ~/.claude/.
  • Sanitization: Absent; the skill relies on simple text parsing of XML and Markdown content without explicit filtering or sanitization of potential injection strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 08:46 AM
Security Audit — agent-trust-hub — ArXiv