fetch-preprint-recent

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches preprint metadata and abstracts from api.biorxiv.org. This is a well-known scientific service, and the use of the API is essential to the skill's primary function of literature scanning.\n- [INDIRECT_PROMPT_INJECTION]: As the skill ingests external data (preprint abstracts and titles) that is returned to the agent's context, it has a potential surface for indirect prompt injection.\n
  • Ingestion points: Metadata is retrieved from the collection field of the bioRxiv API response in SKILL.md.\n
  • Boundary markers: The instructions do not define specific delimiters or "ignore instructions" tags for the abstract content returned to the agent.\n
  • Capability inventory: The skill uses WebFetch for API calls and performs local file writes to the .cache/ directory to store raw metadata.\n
  • Sanitization: No explicit text sanitization or filtering for prompt injection markers is mentioned in the processing steps.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 AM
Security Audit — agent-trust-hub — fetch-preprint-recent