citation-verify

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from user-provided BibTeX files and manuscript drafts, as well as metadata returned from external DOI lookup services. Maliciously crafted citations could contain instructions designed to influence the agent's behavior during the report generation phase.
  • Ingestion points: Processes content from .bib files and manuscript drafts (e.g., .md, .tex, or plain text files) to extract citation strings.
  • Boundary markers: The skill does not define explicit delimiters or "ignore instructions" wrappers for the extracted citation text before processing.
  • Capability inventory: The skill has the capability to read local files, perform network operations via the bibverify MCP tool, and write new files to the output/ directory.
  • Sanitization: The skill performs Unicode NFKC normalization and SHA1 hashing for generating directory names (slugs), but it does not specify sanitization for the citation content itself.
  • [EXTERNAL_DOWNLOADS]: The skill depends on an external MCP server named bibverify. If not present, it instructs the user to install and run it via uvx bibverify mcp, which downloads the package from a Python registry.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:25 PM
Security Audit — agent-trust-hub — citation-verify