arxiv
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill facilitates searching for academic papers using the official arXiv API. All network activity is confined to known academic domains including export.arxiv.org, arxiv.org, and ar5iv.org.
- [SAFE]: File system access is limited to the 'download' command, which saves PDF files to a user-provided path. The filename construction logic uses a sanitized arXiv ID (validated via regular expression), preventing path traversal vulnerabilities.
- [SAFE]: The skill does not contain any obfuscated instructions, hidden URLs, or persistence mechanisms. Its dependency on the 'typer' package is a standard practice for creating command-line interfaces.
- [SAFE]: The tool incorporates an indirect prompt injection surface by processing external paper metadata (titles and abstracts). This risk is mitigated by the use of structured JSON output which helps the calling agent distinguish between data and instructions.
Audit Metadata