deep-research

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions for the timeline_extraction_agent include the use of the pdftotext shell utility to extract publication dates from local PDF files. This is a standard document processing operation within the context of academic research.
  • [EXTERNAL_DOWNLOADS]: The pipeline interacts with several well-known academic metadata services, including the Semantic Scholar API (api.semanticscholar.org), the Crossref API (api.crossref.org), and the OpenAlex API (api.openalex.org). These connections are used exclusively for verifying reference existence and retrieving bibliographic metadata.
  • [INDIRECT_PROMPT_INJECTION]: As a research tool, the skill is designed to ingest and analyze external data from academic papers and search results. This represents a potential indirect prompt injection surface. The skill mitigates this risk through its multi-agent architecture, which includes mandatory 'Devil's Advocate' and 'Ethics Review' checkpoints to verify the integrity and neutrality of the synthesized content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 05:26 AM
Security Audit — agent-trust-hub — deep-research