citation-verify
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input from user-provided BibTeX files and manuscript drafts, as well as metadata returned from external DOI lookup services. Maliciously crafted citations could contain instructions designed to influence the agent's behavior during the report generation phase.
- Ingestion points: Processes content from
.bibfiles and manuscript drafts (e.g.,.md,.tex, or plain text files) to extract citation strings. - Boundary markers: The skill does not define explicit delimiters or "ignore instructions" wrappers for the extracted citation text before processing.
- Capability inventory: The skill has the capability to read local files, perform network operations via the
bibverifyMCP tool, and write new files to theoutput/directory. - Sanitization: The skill performs Unicode NFKC normalization and SHA1 hashing for generating directory names (slugs), but it does not specify sanitization for the citation content itself.
- [EXTERNAL_DOWNLOADS]: The skill depends on an external MCP server named
bibverify. If not present, it instructs the user to install and run it viauvx bibverify mcp, which downloads the package from a Python registry.
Audit Metadata