reference-checker
Pass
Audited by Gen Agent Trust Hub on Jun 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a set of instructions designed to guide an AI agent through a structured verification process for academic references. It does not include scripts, executables, or commands that interact with the host system's sensitive files.
- [DATA_EXPOSURE]: The skill directs the AI to use well-known scholarly services (e.g., PubMed, CNKI, Wanfang, Crossref) to verify metadata. These interactions are consistent with the skill's primary purpose and do not involve the handling of sensitive user credentials or private data.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input (user-supplied reference lists). While this presents a surface for indirect prompt injection, the instructions provide a rigid reporting structure and limit the AI's actions to informational verification, which significantly mitigates the risk of malicious instructions in the data influencing the agent's behavior. Evidence found in
SKILL.mdshows clear boundary definitions for parsing and reporting. - [REMOTE_CODE_EXECUTION]: There is no evidence of remote code execution. The skill explicitly states in its documentation that it is a prompt-based skill with no external code dependencies.
Audit Metadata