literature-review
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill requires the installation of
parallel-cliviacurl -fsSL https://parallel.ai/install.sh | bash. This pattern executes a remote shell script from a third-party domain (parallel.ai) that is not included in the trusted vendor list, posing a significant risk of arbitrary code execution.\n- [INDIRECT_PROMPT_INJECTION]: The skill synthesizes data from external research papers and web results, creating a surface for indirect prompt injection where malicious instructions in academic content could influence agent behavior.\n - Ingestion points: Data retrieved from PubMed, arXiv, and general web searches via
parallel-cli search, stored in thesources/directory.\n - Boundary markers: Absent. The skill does not use delimiters or explicit instructions to isolate untrusted research data within the prompt context during the synthesis phase.\n
- Capability inventory: Access to the
Bashtool, file system write access, and execution of system tools likepandocthroughscripts/generate_pdf.py.\n - Sanitization: Absent. There is no logic provided to sanitize, filter, or escape academic text before it is interpolated into prompts or synthesized into the final review document.\n- [COMMAND_EXECUTION]: The scripts
scripts/generate_pdf.pyandscripts/generate_schematic.pyutilizesubprocess.runto execute external binary tools such aspandocandxelatex, as well as child Python scripts, which could be exploited if arguments are not properly handled.
Recommendations
- HIGH: Downloads and executes remote code from: https://parallel.ai/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata