search-paper
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple academic APIs which could potentially contain malicious instructions aimed at influencing the agent's behavior.
- Ingestion points: Abstracts, titles, and publication metadata retrieved by
arxiv.py,iacr.py,semantic_scholar.py,dblp.py, andopenalex.py. - Boundary markers: Absent; the
SKILL.mdinstructions do not define delimiters or explicit "ignore embedded instructions" headers for processing external paper content. - Capability inventory: The skill includes file-writing capabilities (downloading PDFs to
reaper-workspace/papers/viaarxiv.pyandiacr.py) and network access for API interactions. - Sanitization: Scripts perform text normalization (whitespace and newline removal) but do not implement specific sanitization or filtering for prompt injection patterns.
- [COMMAND_EXECUTION]: The skill invokes local Python drivers to perform its operations, involving network requests and filesystem writes.
- Evidence: Commands such as
python3 arxiv.py download <id> --output-dir <dir>execute shell commands that write files based on agent-provided arguments. - [EXTERNAL_DOWNLOADS]: The skill fetches metadata and downloads files from established academic repositories.
- Evidence: Downloads and API requests targeting
arxiv.org,eprint.iacr.org,dblp.org,api.openalex.org, andapi.semanticscholar.org.
Audit Metadata