skills/rimagination/vpnsci/instsci/Gen Agent Trust Hub

instsci

Warn

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing PowerShell commands and the instsci CLI to manage paper retrieval workflows. It uses Start-Process with hidden windows and redirected output to run background Python tasks and system-level helpers.
  • [REMOTE_CODE_EXECUTION]: The skill's documentation provides PowerShell playbooks that utilize Add-Type to compile C# code at runtime. This code interfaces with the Windows UI Automation API and Win32 functions (ShowWindowAsync, SetForegroundWindow) to programmatically control browser windows and simulate user interactions, representing a sophisticated form of dynamic execution.
  • [CREDENTIALS_UNSAFE]: The workflow involves configuring Elsevier API keys and managing institutional authentication states (e.g., CARSI, Shibboleth, OpenAthens). Although the skill explicitly warns against logging secrets or automating password entry, it facilitates the handling of sensitive session data like cookies and identity policies.
  • [EXTERNAL_DOWNLOADS]: The core functionality involves downloading PDF documents from reputable academic publishing platforms such as ScienceDirect, ACS, and Wiley. These operations are conducted as part of the tool's primary purpose.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of external DOI lists (dois.txt) and repository JSON files. It lacks explicit boundary markers or sanitization for this untrusted data. Given its capability inventory—which includes system-level command execution and UI automation—this creates a pathway where malicious content in processed documents could attempt to influence agent behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 5, 2026, 01:05 AM
Security Audit — agent-trust-hub — instsci