paperzilla

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves retrieving and summarizing external research papers, which constitutes a surface for indirect prompt injection attacks.
  • Ingestion points: External data enters the agent's context through commands such as pz paper <id> --markdown and pz rec <id> --markdown, as described in SKILL.md.
  • Boundary markers: The instructions do not specify the use of delimiters or 'ignore' instructions to isolate untrusted external content from the agent's core prompt.
  • Capability inventory: The skill utilizes the pz CLI for data retrieval and feedback submission but does not include capabilities for arbitrary filesystem writes or general-purpose network exfiltration.
  • Sanitization: There are no protocols defined within the skill for sanitizing or filtering instructions that might be embedded in the retrieved markdown content.
  • [EXTERNAL_DOWNLOADS]: The skill provides procedures for installing the pz CLI from official vendor resources, including GitHub repositories under the 'paperzilla-ai' organization and the 'paperzilla.ai' documentation domain.
  • [COMMAND_EXECUTION]: All primary functions of the skill are performed by executing the pz CLI tool. This requires the agent to trigger local process execution for tasks like listing projects and fetching paper details.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — paperzilla