pp-zotero-research-library
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill requires the installation of external components from the vendor's GitHub repository and NPM organization (@mvanhorn).
- [COMMAND_EXECUTION]: The installation process involves executing shell commands via
npxandgo installto fetch and compile the research library CLI tools. - [DATA_EXFILTRATION]: The tool features a built-in
--deliver webhook:<url>capability, which allows the agent to POST research data to arbitrary external endpoints as a documented feature. - [INDIRECT_PROMPT_INJECTION]: The skill processes research items from the user's Zotero library, which could potentially contain malicious instructions intended to influence agent behavior.
- Ingestion points: Zotero API sync and local SQLite search results.
- Boundary markers: No specific delimiters or safety instructions are defined in the skill to separate ingested research data from agent commands.
- Capability inventory: The agent can execute the CLI binary, which has network access and file system write permissions.
- Sanitization: No explicit sanitization or filtering of bibliographic content is performed at the prompt level before processing.
- [DYNAMIC_EXECUTION]: The 'Playbook' and 'Automatic Learning' features involve the dynamic synthesis and execution of command sequences stored in local JSON files, representing a form of runtime behavior generation based on session journals.
Audit Metadata