researchclaw-cn

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the researchclaw package and its dependencies via pip and clones the source code from github.com/aiming-lab/AutoResearchClaw. It also suggests using a well-known academic mirror (tsinghua.edu.cn) for faster downloads in certain regions.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on untrusted data from two primary sources: user-provided research topics and academic literature fetched from arXiv and Semantic Scholar. This data is processed by an agentic pipeline with the capability to execute shell commands and write files.
  • Ingestion points: Research topics provided in the /researchclaw:run command and literature retrieved during the 'Literature Search' and 'Literature Analysis' stages.
  • Boundary markers: None detected in the skill scripts; there are no explicit delimiters to segregate paper content from agent instructions.
  • Capability inventory: The skill has access to Bash (executing the ResearchClaw CLI, Docker, and Python), Read, and Write tools.
  • Sanitization: The skill's scripts do not perform explicit sanitization of the retrieved literature content before it is processed by the pipeline.
  • [COMMAND_EXECUTION]: The skill utilizes several local shell scripts to manage its lifecycle. check-prereqs.sh verifies system dependencies, pre-config-write.sh performs backups, and notify-completion.sh uses system utilities like osascript (macOS) or notify-send (Linux) to provide desktop notifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:23 AM
Security Audit — agent-trust-hub — researchclaw-cn