reference-manager-interop
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external bibliographic data files (RIS, BibTeX, CSL-JSON), which are untrusted inputs. This represents an attack surface for indirect prompt injection if an attacker crafts malicious library entries designed to influence the agent when it reads the file contents.
- Ingestion points: The script
scripts/convert_refs.pyreads bibliographic data from files provided as input arguments in the file system. - Boundary markers: The instructions do not include specific delimiters or warnings to the agent regarding untrusted content in the processed files.
- Capability inventory: The skill has file-write and file-read capabilities through the provided conversion script.
- Sanitization: No specific prompt injection sanitization is performed on the data during conversion; it uses standard regex and JSON parsing.
- [SAFE]: The provided Python script
scripts/convert_refs.pyuses only the standard library and performs local file transformations without network access or sensitive file interaction. - [SAFE]: References to external style repositories point to well-known, community-maintained resources on GitHub, such as the official Citation Style Language (CSL) repository.
Audit Metadata