literature-review
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructions include a command to install the
uvtool by downloading and executing a script fromhttps://astral.sh/uv/install.sh. This is a documented installation method for a well-known development tool. - [EXTERNAL_DOWNLOADS]: The skill connects to established scholarly services, including OpenAlex, arXiv, and Europe PMC, to retrieve academic metadata and full-text documents. These are recognized services within the research community.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external academic papers.
- Ingestion points: External research papers (PDF, XML) are ingested and converted to markdown in
scripts/read_paper.py. - Boundary markers: The instructions command the agent to process papers one at a time and maintain a structured protocol to prevent context pollution.
- Capability inventory: The skill possesses the ability to perform network requests and write files to a local workspace.
- Sanitization: The skill uses
xml.etree.ElementTreefor XML parsing andpymupdf4llmfor PDF extraction, which are standard utilities for these tasks. - [COMMAND_EXECUTION]: The skill instructions direct the agent to execute internal Python scripts using the
uv runcommand to automate the research workflow.
Audit Metadata