semanticscholar-skill

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill utilizes a workflow where the agent generates a Python script (/tmp/s2_search.py) to perform API searches. It also performs dynamic path resolution for the s2.py library by searching several standard skill installation paths (e.g., ~/.claude/skills/, ~/.openclaw/skills/) and prepending the discovered directory to sys.path.
  • [COMMAND_EXECUTION]: The skill requires the agent to execute the generated Python search scripts via the python3 command. This execution is limited to the local environment and specifically targets the provided API helper module.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external content from the Semantic Scholar API, such as paper abstracts and titles, which constitutes a potential attack surface for indirect prompt injection.
  • Ingestion points: Data enters the agent's context through search results and paper details fetched via s2.py functions.
  • Boundary markers: The skill uses structured Markdown tables and detailed blocks to present data, providing some separation, but lacks explicit "ignore instructions" delimiters for the API content.
  • Capability inventory: The skill allows the agent to write files (results and scripts), perform network requests to official Semantic Scholar endpoints, and execute Python code.
  • Sanitization: The s2.py module performs basic truncation and formatting of API data for display, but does not perform semantic sanitization to filter out potential instructions hidden in academic metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 03:43 AM
Security Audit — agent-trust-hub — semanticscholar-skill