pubmed-database

Pass

Audited by Gen Agent Trust Hub on Sep 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill communicates with the official NCBI PubMed E-utilities API (eutils.ncbi.nlm.nih.gov) to fetch literature data. This is a well-known and legitimate service for medical research information.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and displays article titles and abstracts from PubMed, which are external, user-contributed texts that could contain adversarial instructions targeting the agent context.
  • Ingestion points: External research data enters the system through the search and fetch commands located in cli/src/commands/search.ts and cli/src/commands/fetch.ts.
  • Boundary markers: The current implementation does not utilize explicit boundary markers or delimiters when presenting the retrieved abstract text to the agent.
  • Capability inventory: The skill provides network access to the NCBI API and outputs data to the console, but it does not have the capability to write to the file system or execute arbitrary shell commands based on the retrieved content.
  • Sanitization: The skill performs standard JSON and text parsing but does not specifically filter or sanitize the content of the abstracts for potential prompt injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 2, 2026, 09:02 PM