bgpt-paper-search
Warn
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill use s 'npx' to download and exec ute the 'bgpt-mcp' package and the 'mcp-remote' tool from the npm registry. The se re source s are not associate d with a pre-verifie d truste d ven dor.
- [COMMAND_EXECUTION]: The setu p instruc tio n s require the agen t to exec ute shel l comman d s using 'npx' to con figure the mcpServe r s etting s.
- [PROMPT_INJECTION]: The skill pro c e s se s struc ture d data extrac te d from ful l-text scie n tific pape r s, whic h pre sen t s a vul nerabil ity surface for indirec t prompt injec tio n if retrie ve d con ten t con tain s mal icio us instruc tio n s.
- Ingestio n poin t s: Data retrie ve d via the 'searc h_pape r s' tool output.
- Boun dary marke r s: No expl icit del im ite r s or 'ignore' warning s pre sen t in the tool des c riptio n to separate data from comman d s.
- Capabil ity inven tory: The skill is gran te d acc e s s to 'Bash' and exec ute s shel l comman d s via 'npx'.
- Sanitizatio n: No eviden c e of sanitizatio n or val idatio n of the retrie ve d scie n tific data is pro vide d.
Audit Metadata