get-paper

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious code or suspicious patterns were identified in the analysis. The skill's functionality, which involves navigating to Google Scholar and managing local bibliography files, is consistent with its stated purpose.- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection because it ingests untrusted data from web search results (paper titles and citation metadata). However, the risk is minimal given the specific context of use. 1. Ingestion points: Search results and citation pages on scholar.google.com. 2. Boundary markers: Absent. 3. Capability inventory: Browser automation via Chrome DevTools MCP and read/write operations for local .bib files. 4. Sanitization: No explicit sanitization or validation of the extracted web content is performed.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 06:14 AM
Security Audit — agent-trust-hub — get-paper