skills/grahama1970/agent-skills/arxiv/Gen Agent Trust Hub

arxiv

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads research paper metadata and content from official arXiv API endpoints (export.arxiv.org) and ar5iv.org. These sources are reputable academic repositories.
  • [COMMAND_EXECUTION]: Orchestrates complex workflows by executing entry-point scripts of sibling skills within the same environment (e.g., extractor, qra, memory, interview). These subprocess calls use defined arguments and do not incorporate unvalidated external input into shell commands.
  • [PROMPT_INJECTION]: While the skill processes untrusted data from academic papers (Indirect Prompt Injection surface), it implements strong mitigations. The extraction prompts enforce structured JSON output, and a mandatory 'interview' stage requires human confirmation to review and approve extracted knowledge before it is stored in the memory database.
  • [DATA_EXFILTRATION]: No unauthorized data transmission was detected. Network activity is limited to fetching research data from trusted domains, and all processed information is stored in a local memory system managed by the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:34 AM
Security Audit — agent-trust-hub — arxiv