journal-abbrev

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands via the ! syntax (e.g., !git status), but these are limited to common development workflows (git, gh) and are documented neutrally. The core functionality uses python3 to run a local script (jabbrv.py), which is the intended purpose of the skill.
  • [EXTERNAL_DOWNLOADS]: The skill downloads academic journal abbreviation lists from a well-known GitHub repository (JabRef/abbrv.jabref.org). These downloads are performed using atomic staging (downloading to a .new directory before swapping) and are restricted to CSV data files. This is a legitimate functional requirement for the skill's local cache.
  • [DATA_EXPOSURE]: The skill reads and writes .bib files and text files for journal processing. These operations are scoped to paths provided by the user. The skill respects system-level environment variables for cache directories and does not access sensitive system paths or credentials.
  • [REMOTE_CODE_EXECUTION]: While the skill interacts with external APIs (AbbrevISO on Toolforge and NLM E-utilities), it only processes structured data (JSON/XML/Text). It does not download or execute remote scripts or binary payloads.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied journal names and BibTeX content. While this is an ingestion surface for untrusted data, the skill's output is structured (JSON/Table) and its capabilities are limited to string manipulation and local file writes, minimizing the risk of multi-step injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — journal-abbrev