researchclaw-cn
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the
researchclawpackage and its dependencies viapipand clones the source code fromgithub.com/aiming-lab/AutoResearchClaw. It also suggests using a well-known academic mirror (tsinghua.edu.cn) for faster downloads in certain regions. - [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from two primary sources: user-provided research topics and academic literature fetched from arXiv and Semantic Scholar. This data is processed by an agentic pipeline with the capability to execute shell commands and write files.
- Ingestion points: Research topics provided in the
/researchclaw:runcommand and literature retrieved during the 'Literature Search' and 'Literature Analysis' stages. - Boundary markers: None detected in the skill scripts; there are no explicit delimiters to segregate paper content from agent instructions.
- Capability inventory: The skill has access to
Bash(executing the ResearchClaw CLI, Docker, and Python),Read, andWritetools. - Sanitization: The skill's scripts do not perform explicit sanitization of the retrieved literature content before it is processed by the pipeline.
- [COMMAND_EXECUTION]: The skill utilizes several local shell scripts to manage its lifecycle.
check-prereqs.shverifies system dependencies,pre-config-write.shperforms backups, andnotify-completion.shuses system utilities likeosascript(macOS) ornotify-send(Linux) to provide desktop notifications.
Audit Metadata