semanticscholar-skill
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill utilizes a workflow where the agent generates a Python script (
/tmp/s2_search.py) to perform API searches. It also performs dynamic path resolution for thes2.pylibrary by searching several standard skill installation paths (e.g.,~/.claude/skills/,~/.openclaw/skills/) and prepending the discovered directory tosys.path. - [COMMAND_EXECUTION]: The skill requires the agent to execute the generated Python search scripts via the
python3command. This execution is limited to the local environment and specifically targets the provided API helper module. - [INDIRECT_PROMPT_INJECTION]: The skill processes external content from the Semantic Scholar API, such as paper abstracts and titles, which constitutes a potential attack surface for indirect prompt injection.
- Ingestion points: Data enters the agent's context through search results and paper details fetched via
s2.pyfunctions. - Boundary markers: The skill uses structured Markdown tables and detailed blocks to present data, providing some separation, but lacks explicit "ignore instructions" delimiters for the API content.
- Capability inventory: The skill allows the agent to write files (results and scripts), perform network requests to official Semantic Scholar endpoints, and execute Python code.
- Sanitization: The
s2.pymodule performs basic truncation and formatting of API data for display, but does not perform semantic sanitization to filter out potential instructions hidden in academic metadata.
Audit Metadata