paper-navigator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches academic data and paper content from well-known services including Semantic Scholar, arXiv (via the DeepXiv SDK), HuggingFace, GitHub, Jina Reader, and Unpaywall.
  • [COMMAND_EXECUTION]: Operates by executing local Python scripts to perform searches, citation analysis, and paper downloads. These scripts are part of the skill's distribution.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external academic sources. It implements a 'quote-or-zero' rule requiring the agent to provide short (<=80 character) verbatim evidence for its relevance claims, which serves as a safeguard against hallucination and indirect injection.
  • Ingestion points: External data enters through scholar_search.py, fetch_paper.py, and arxiv_monitor.py.
  • Boundary markers: The agent is instructed to use a specific mask system (✓ / ~ / ✗) and strict quotation rules for evidence.
  • Capability inventory: Uses execute for script running and write_file for saving paper summaries and full texts.
  • Sanitization: Triage logic filters out irrelevant results based on a predefined rubric before final ranking.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:03 AM
Security Audit — agent-trust-hub — paper-navigator