bgpt-paper-search

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill serves as a documentation and instructional guide for interacting with a remote research database. It does not contain executable code within the skill file itself.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external scientific papers via the search_papers tool. This is a known attack surface (Category 8); however, the skill includes explicit 'Integrity rules' and 'Agent operating procedures' requiring the agent to validate results, confirm identifiers, and report uncertainties, which serves as a mitigation for processing untrusted external content.
  • [EXTERNAL_DOWNLOADS]: The documentation references npx mcp-remote and npx bgpt-mcp for environment setup. These are standard procedures for connecting to remote Model Context Protocol (MCP) servers and are consistent with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — bgpt-paper-search