paper-analyzer
Pass
Audited by Gen Agent Trust Hub on May 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were identified. The skill's behavior is consistent with its stated purpose of academic paper analysis.- [EXTERNAL_DOWNLOADS]: The skill utilizes 'notebooklm-py' (a third-party tool for interacting with Google NotebookLM) and fetches data from well-known academic services including arXiv and the Semantic Scholar API. These interactions are documented and necessary for the skill's primary functionality.- [COMMAND_EXECUTION]: The skill uses the 'notebooklm' CLI to manage research sources and perform source-grounded queries. These shell commands are used for their intended purpose in a research workflow.- [DATA_EXFILTRATION]: The skill reads project-specific reference files (hypothesis.md and taxonomy.md) and public academic content. No access to sensitive system files, environment variables, or private credentials was found.- [PROMPT_INJECTION]: The skill is designed to ingest and analyze external documents (academic papers), which inherently creates an 'Indirect Prompt Injection' surface. However, the instructions mandate a 'critical analysis' approach, which requires the agent to dissect and challenge paper claims rather than blindly following the content, providing a degree of natural protection against embedded instructions.
Audit Metadata