paper-lookup

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches scholarly data from well-known academic APIs including ArXiv, PubMed, OpenAlex, and Crossref. These services are recognized as reputable scholarly sources, and the data retrieval is performed via standard API endpoints.
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute curl commands and pipes the output to local Python scripts for parsing. While automated scans may flag the piping of remote content to python3, analysis confirms that the interpreter is used to execute local, bundled scripts (e.g., scripts/arxiv_atom.py) which process the downloaded data as input via stdin, rather than executing the downloaded content as code.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party data from scholarly papers, which represents a potential injection surface.
  • Ingestion points: Data enters the agent's context through search results from 18 scholarly APIs as documented in the references/ directory.
  • Boundary markers: The skill provides explicit instructions to the agent to quote relevant data slices and label them as untrusted third-party content to prevent confusion with instructions.
  • Capability inventory: The skill has access to the Bash tool for network requests and identifies the capability to save large payloads to local files.
  • Sanitization: The bundled utility scripts/_common.py provides functions like strip_control and collapse_ws to remove control characters and normalize whitespace in API responses, mitigating risks from malformed or engineered text payloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — paper-lookup