citation-management

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes citation metadata from external research databases (CrossRef, PubMed, arXiv, OpenAlex) which could contain malicious strings.
  • Ingestion points: Metadata is ingested via API responses in extract_metadata.py, search_pubmed.py, search_openalex.py, and search_google_scholar.py.
  • Boundary markers: SKILL.md contains a prominent security section titled 'Treat extracted metadata as untrusted' that warns against shell injection.
  • Capability inventory: The skill uses requests for network access and Write/Edit tools for file management. It suggests using subprocess for execution.
  • Sanitization: scripts/_common.py includes a sanitize_key function and SKILL.md provides specific code examples for safe argument escaping and Python subprocess usage without shell=True.
  • [EXTERNAL_DOWNLOADS]: The skill fetches citation metadata from well-known academic APIs including api.openalex.org, api.crossref.org, eutils.ncbi.nlm.nih.gov, export.arxiv.org, and api.datacite.org. These are legitimate research infrastructure sources and no executable code is downloaded from these endpoints.
  • [CREDENTIALS_UNSAFE]: The scripts read optional environment variables (NCBI_API_KEY, NCBI_EMAIL, OPENALEX_EMAIL) to raise rate limits or identify callers to academic services. These are standard practices for these specific APIs and are documented in the skill's frontmatter.
  • [DYNAMIC_EXECUTION]: The bundled scripts use __import__("pathlib") for cross-platform path resolution during module setup. This is a benign use of dynamic loading for standard library components.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — citation-management