search-paper

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple academic APIs which could potentially contain malicious instructions aimed at influencing the agent's behavior.
  • Ingestion points: Abstracts, titles, and publication metadata retrieved by arxiv.py, iacr.py, semantic_scholar.py, dblp.py, and openalex.py.
  • Boundary markers: Absent; the SKILL.md instructions do not define delimiters or explicit "ignore embedded instructions" headers for processing external paper content.
  • Capability inventory: The skill includes file-writing capabilities (downloading PDFs to reaper-workspace/papers/ via arxiv.py and iacr.py) and network access for API interactions.
  • Sanitization: Scripts perform text normalization (whitespace and newline removal) but do not implement specific sanitization or filtering for prompt injection patterns.
  • [COMMAND_EXECUTION]: The skill invokes local Python drivers to perform its operations, involving network requests and filesystem writes.
  • Evidence: Commands such as python3 arxiv.py download <id> --output-dir <dir> execute shell commands that write files based on agent-provided arguments.
  • [EXTERNAL_DOWNLOADS]: The skill fetches metadata and downloads files from established academic repositories.
  • Evidence: Downloads and API requests targeting arxiv.org, eprint.iacr.org, dblp.org, api.openalex.org, and api.semanticscholar.org.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 08:28 AM
Security Audit — agent-trust-hub — search-paper