literature-tracking

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with well-known and reputable academic databases such as arXiv, bioRxiv, PubMed, and Europe PMC. These sources are established research infrastructure and are used solely for retrieving publication metadata.
  • [SAFE]: Authentication for services like NCBI is handled correctly through environment variables (e.g., NCBI_API_KEY), adhering to standard security practices for managing sensitive configuration.
  • [SAFE]: The entire codebase is implemented using the Python standard library, which eliminates the security risks associated with third-party package dependencies and supply chain attacks.
  • [SAFE]: The skill includes robust internal controls for rate-limiting and request pacing, ensuring respectful and compliant usage of external research APIs.
  • [SAFE]: Although the skill ingests external paper abstracts, the risk of indirect prompt injection is minimal given that the data originates from audited academic repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 02:03 PM
Security Audit — agent-trust-hub — literature-tracking