implement-paper-auto

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches and processes paper content from alphaxiv.org, which creates a potential surface for indirect prompt injection. * Ingestion points: Markdown summaries and full paper text fetched via curl in SKILL.md. * Boundary markers: No explicit instructions to treat the fetched content as untrusted data or use delimiters to isolate it from agent instructions. * Capability inventory: The skill generates marimo notebooks and anywidget components, involving Python and JavaScript code generation across SKILL.md and ANYWIDGET.md. * Sanitization: There are no instructions to sanitize or validate the content fetched from the external site before using it to influence notebook generation.
  • [EXTERNAL_DOWNLOADS]: Fetches data from alphaxiv.org using curl to retrieve paper overviews and full text. While this targets a well-known research service, the agent fetches external content at runtime.
  • [DYNAMIC_EXECUTION]: Generates anywidget components which involve embedding and executing JavaScript ESM code within a Python class structure. The skill provides templates for creating these dynamic UI elements.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:50 AM
Security Audit — agent-trust-hub — implement-paper-auto