oma-scholar
Pass
Audited by Gen Agent Trust Hub on May 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for academic research and sidecar generation using the Knows specification. It interacts with known scholarly services including knows.academy and OpenAlex. The skill handles user-provided API keys for OpenAlex via standard environment variables, which is a safe practice. It also includes a validation step (
oma scholar lint) to verify the structure of generated sidecars. - [SAFE]: The skill explicitly avoids dangerous patterns; for example, it instructs the host LLM to generate content directly rather than shelling out to external SDKs, and it provides a local validation tool to avoid dependencies on unverified third-party packages. No evidence of obfuscation, exfiltration to untrusted domains, or unauthorized privilege escalation was found.
Audit Metadata