oma-scholar
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches academic paper metadata and structured sidecars from public research services including Knows Academy and OpenAlex.
- [COMMAND_EXECUTION]: Executes the
oma scholarCLI for searching academic databases and validating locally generated YAML sidecar files. - [CREDENTIALS_UNSAFE]: Includes instructions for the management of API keys for OpenAlex, which advise users to store credentials in local environment variables or .env files rather than hardcoding them.
- [PROMPT_INJECTION]: The skill processes untrusted data from research papers and remote sidecars; it provides validation via a linting tool and specific anti-fabrication instructions to mitigate the risks of indirect prompt injection.
Audit Metadata