pyzotero
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to retrieve and process research data from external, untrusted sources including the Zotero Web API and Semantic Scholar. This content (abstracts, full-text PDFs, and metadata) could be used as a vector for indirect prompt injection if it contains adversarial instructions intended to influence the agent's behavior.
- Ingestion points: Bibliographic metadata retrieval (references/read-api.md), full-text attachment content indexing (references/full-text.md), and Semantic Scholar search tools (references/mcp.md).
- Boundary markers: The instructions do not define specific delimiters or instructions to ignore embedded commands when processing retrieved content.
- Capability inventory: The skill provides the agent with access to
Write,Edit, andBashtools, which increases the potential impact of a successful injection. - Sanitization: No specific mechanisms for sanitizing or filtering the external bibliographic data before interpolation into prompts are mentioned.
- [METADATA_POISONING]: The skill's documentation and frontmatter reference a version of the
pyzoterolibrary (1.13.0, dated May 2026) and specific feature sets like the MCP server and CLI extras that do not currently exist in the official upstream repository. This represents misleading metadata regarding the required software environment.
Audit Metadata