inno-reference-audit

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external BibTeX and LaTeX files provided by the user to verify academic references. This ingestion of untrusted data represents a potential surface for indirect prompt injection if the agent interprets citation content as instructions.
  • Ingestion points: External files loaded as arguments for scripts/verify-citations.py and scripts/format-checker.py.
  • Boundary markers: The scripts do not explicitly use boundary markers to separate citation data from potential instructions during the parsing process.
  • Capability inventory: The skill has access to network operations (requests.get), file system access (read_file, write_file), and terminal execution (run_terminal).
  • Sanitization: The scripts utilize the bibtexparser library for BibTeX files and regular expressions for LaTeX extraction, providing structured parsing rather than raw text interpolation.
  • [EXTERNAL_DOWNLOADS]: The Python scripts in the scripts/ directory perform network requests to fetch paper metadata from well-known academic APIs, including api.crossref.org, doi.org, export.arxiv.org, and api.semanticscholar.org.
  • [COMMAND_EXECUTION]: The skill is configured to use the run_terminal tool, which is employed to run the bundled Python scripts for citation verification and format checking against user-supplied bibliography files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:58 PM