literature-review

Fail

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill requires the installation of parallel-cli via curl -fsSL https://parallel.ai/install.sh | bash. This pattern executes a remote shell script from a third-party domain (parallel.ai) that is not included in the trusted vendor list, posing a significant risk of arbitrary code execution.\n- [INDIRECT_PROMPT_INJECTION]: The skill synthesizes data from external research papers and web results, creating a surface for indirect prompt injection where malicious instructions in academic content could influence agent behavior.\n
  • Ingestion points: Data retrieved from PubMed, arXiv, and general web searches via parallel-cli search, stored in the sources/ directory.\n
  • Boundary markers: Absent. The skill does not use delimiters or explicit instructions to isolate untrusted research data within the prompt context during the synthesis phase.\n
  • Capability inventory: Access to the Bash tool, file system write access, and execution of system tools like pandoc through scripts/generate_pdf.py.\n
  • Sanitization: Absent. There is no logic provided to sanitize, filter, or escape academic text before it is interpolated into prompts or synthesized into the final review document.\n- [COMMAND_EXECUTION]: The scripts scripts/generate_pdf.py and scripts/generate_schematic.py utilize subprocess.run to execute external binary tools such as pandoc and xelatex, as well as child Python scripts, which could be exploited if arguments are not properly handled.
Recommendations
  • HIGH: Downloads and executes remote code from: https://parallel.ai/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — literature-review