paper-fetch
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is designed to download PDF files from various academic repositories and search APIs, including Unpaywall, Semantic Scholar, arXiv, PubMed Central, and bioRxiv.
- [COMMAND_EXECUTION]: The script uses
subprocess.runto invoke a companion script (cloak_pdf.py) for handling browser-based downloads and to check for the presence of thecloakbrowserPython dependency. - [SAFE]: Implements extensive Server-Side Request Forgery (SSRF) protection. It validates all URLs and resolved IP addresses against a blocklist that includes loopback aliases, private IP ranges (RFC 1918), and cloud metadata endpoints (Google, AWS) in both the main script and its companion.
- [SAFE]: Enforces security checks on all downloaded content, verifying the
%PDFmagic bytes at the start of the file and imposing a 50 MB size limit to prevent resource exhaustion attacks. - [SAFE]: Uses
shlex.quotewhen generating suggested follow-up commands in the output, preventing potential command injection if a user-provided DOI contains malicious shell characters. - [SAFE]: Browser automation for bypassing Cloudflare (via CloakBrowser) and institutional access modes are strictly opt-in via environment variables set by the operator, maintaining a clear trust boundary.
Audit Metadata