inno-reference-audit
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external BibTeX and LaTeX files provided by the user to verify academic references. This ingestion of untrusted data represents a potential surface for indirect prompt injection if the agent interprets citation content as instructions.
- Ingestion points: External files loaded as arguments for
scripts/verify-citations.pyandscripts/format-checker.py. - Boundary markers: The scripts do not explicitly use boundary markers to separate citation data from potential instructions during the parsing process.
- Capability inventory: The skill has access to network operations (
requests.get), file system access (read_file,write_file), and terminal execution (run_terminal). - Sanitization: The scripts utilize the
bibtexparserlibrary for BibTeX files and regular expressions for LaTeX extraction, providing structured parsing rather than raw text interpolation. - [EXTERNAL_DOWNLOADS]: The Python scripts in the
scripts/directory perform network requests to fetch paper metadata from well-known academic APIs, includingapi.crossref.org,doi.org,export.arxiv.org, andapi.semanticscholar.org. - [COMMAND_EXECUTION]: The skill is configured to use the
run_terminaltool, which is employed to run the bundled Python scripts for citation verification and format checking against user-supplied bibliography files.
Audit Metadata