literature-review

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill instructions include a command to install the uv tool by downloading and executing a script from https://astral.sh/uv/install.sh. This is a documented installation method for a well-known development tool.
  • [EXTERNAL_DOWNLOADS]: The skill connects to established scholarly services, including OpenAlex, arXiv, and Europe PMC, to retrieve academic metadata and full-text documents. These are recognized services within the research community.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from external academic papers.
  • Ingestion points: External research papers (PDF, XML) are ingested and converted to markdown in scripts/read_paper.py.
  • Boundary markers: The instructions command the agent to process papers one at a time and maintain a structured protocol to prevent context pollution.
  • Capability inventory: The skill possesses the ability to perform network requests and write files to a local workspace.
  • Sanitization: The skill uses xml.etree.ElementTree for XML parsing and pymupdf4llm for PDF extraction, which are standard utilities for these tasks.
  • [COMMAND_EXECUTION]: The skill instructions direct the agent to execute internal Python scripts using the uv run command to automate the research workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:29 PM
Security Audit — agent-trust-hub — literature-review