paper-lookup
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches scholarly data from well-known academic APIs including ArXiv, PubMed, OpenAlex, and Crossref. These services are recognized as reputable scholarly sources, and the data retrieval is performed via standard API endpoints.
- [COMMAND_EXECUTION]: The skill utilizes the
Bashtool to executecurlcommands and pipes the output to local Python scripts for parsing. While automated scans may flag the piping of remote content topython3, analysis confirms that the interpreter is used to execute local, bundled scripts (e.g.,scripts/arxiv_atom.py) which process the downloaded data as input via stdin, rather than executing the downloaded content as code. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted third-party data from scholarly papers, which represents a potential injection surface.
- Ingestion points: Data enters the agent's context through search results from 18 scholarly APIs as documented in the
references/directory. - Boundary markers: The skill provides explicit instructions to the agent to quote relevant data slices and label them as untrusted third-party content to prevent confusion with instructions.
- Capability inventory: The skill has access to the
Bashtool for network requests and identifies the capability to save large payloads to local files. - Sanitization: The bundled utility
scripts/_common.pyprovides functions likestrip_controlandcollapse_wsto remove control characters and normalize whitespace in API responses, mitigating risks from malformed or engineered text payloads.
Audit Metadata