sn-search-academic
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to fetch and process paper abstracts, titles, and full text from external academic sources such as arXiv, Semantic Scholar, and PubMed.
- Ingestion points: The
search.py,paper.py, andrefTree.pyscripts ingest data from various web APIs and web pages. - Boundary markers: The current implementation does not appear to wrap external content in delimiters or include instructions for the agent to ignore embedded natural language commands.
- Capability inventory: The skill can perform network requests, execute shell commands for helper tools, and write output to local files.
- Sanitization: Content is cleaned of HTML tags and normalized for whitespace, but no semantic filtering is applied to detect or strip potential injection attempts within the scholarly text.
- [COMMAND_EXECUTION]: The skill executes external binaries to support its functionality.
scripts/arxiv_crawler_search.pyandscripts/semantic_scholar_crawler_refTree.pyinvokenodeto executecamoufox-jsfor generating browser launch options.scripts/arxiv_pdf_paper.pyinvokes thepdftotextsystem utility (if found) to perform text extraction from PDF files.- [DYNAMIC_EXECUTION]: The unified entry points (
search.py,paper.py,refTree.py) useimportlib.import_moduleto load specific provider implementations at runtime. - The modules are selected from a static map (
PROVIDER_GROUPS) defined within the source code, which mitigates the risk of loading arbitrary external modules. - [EXTERNAL_DOWNLOADS]: The skill relies on external packages and environment setup.
requirements.txtspecifies several standard libraries along withdeepxiv-sdk, a vendor-specific package from the skill author.- The crawler functionality requires a one-time setup of Playwright browsers (
python3 -m playwright install firefox) andcamoufox-jsvia Node.js.
Audit Metadata