paper-analyzer

Fail

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: HIGHEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches PDF and tarball files from arxiv.org using curl. As arXiv is a well-known and reputable service for academic research, these downloads are considered safe and consistent with the skill's primary intent.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data (academic papers) which could potentially contain malicious instructions intended to influence the agent's behavior during the summary or graph update phase.
  • Ingestion points: Paper content is downloaded from arxiv.org/pdf and arxiv.org/abs into /tmp/paper_analysis/ before being processed by the agent.
  • Boundary markers: The instructions do not include specific delimiters or warnings to the agent to disregard instructions found within the processed paper content.
  • Capability inventory: The agent has access to write_file and run_terminal, which it uses to execute local Python scripts (generate_note.py and update_graph.py) to save analysis results.
  • Sanitization: The bundled Python scripts perform basic string substitution for templates but do not implement formal sanitization or validation of the text extracted from the papers.
  • [COMMAND_EXECUTION]: The skill uses run_terminal to execute curl for fetching papers and to run its local Python scripts. This is standard functional behavior for the described research workflow.
Recommendations
  • HIGH: Downloads and executes remote code from: https://arxiv.org/pdf/[PAPER_ID] - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 21, 2026, 05:58 PM