pp-zotero-research-library

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill requires the installation of external components from the vendor's GitHub repository and NPM organization (@mvanhorn).
  • [COMMAND_EXECUTION]: The installation process involves executing shell commands via npx and go install to fetch and compile the research library CLI tools.
  • [DATA_EXFILTRATION]: The tool features a built-in --deliver webhook:<url> capability, which allows the agent to POST research data to arbitrary external endpoints as a documented feature.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes research items from the user's Zotero library, which could potentially contain malicious instructions intended to influence agent behavior.
  • Ingestion points: Zotero API sync and local SQLite search results.
  • Boundary markers: No specific delimiters or safety instructions are defined in the skill to separate ingested research data from agent commands.
  • Capability inventory: The agent can execute the CLI binary, which has network access and file system write permissions.
  • Sanitization: No explicit sanitization or filtering of bibliographic content is performed at the prompt level before processing.
  • [DYNAMIC_EXECUTION]: The 'Playbook' and 'Automatic Learning' features involve the dynamic synthesis and execution of command sequences stored in local JSON files, representing a form of runtime behavior generation based on session journals.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:16 AM
Security Audit — agent-trust-hub — pp-zotero-research-library