citation-verification
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to
api.crossref.org,api.openalex.org, andexport.arxiv.orgto verify citation metadata against official records. These are well-known services in the research and academic community. - [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses bibliographic data (
.bibfiles) provided by the user. While this data is external and untrusted, the script uses a deterministic comparison logic to generate verification reports, minimizing the risk of instructions embedded in the data influencing the agent's behavior. - Ingestion points: The
scripts/verify_citations.pyscript reads and parses BibTeX files via theparse_bibfunction. - Boundary markers: No explicit instruction delimiters are used when processing the text fields, but the logic is focused on string similarity matching.
- Capability inventory: The script performs network GET requests and file writing (via the
--jsonflag). - Sanitization: The
norm()function provides basic sanitization by removing LaTeX commands and non-alphanumeric characters for metadata comparison. - [COMMAND_EXECUTION]: The skill requires the agent to execute the provided
scripts/verify_citations.pyscript. The script is self-contained and relies exclusively on the Python standard library.
Audit Metadata