bgpt-paper-search
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as a documentation and instructional guide for interacting with a remote research database. It does not contain executable code within the skill file itself.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external scientific papers via the
search_paperstool. This is a known attack surface (Category 8); however, the skill includes explicit 'Integrity rules' and 'Agent operating procedures' requiring the agent to validate results, confirm identifiers, and report uncertainties, which serves as a mitigation for processing untrusted external content. - [EXTERNAL_DOWNLOADS]: The documentation references
npx mcp-remoteandnpx bgpt-mcpfor environment setup. These are standard procedures for connecting to remote Model Context Protocol (MCP) servers and are consistent with the skill's stated purpose.
Audit Metadata