draft-related-work

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/gather_candidates.py script fetches academic metadata (titles, years, abstracts) from Semantic Scholar's API (api.semanticscholar.org). This is a well-known service used for the skill's primary purpose of gathering citation data.- [COMMAND_EXECUTION]: The skill utilizes local Python scripts (audit_bib.py, check_coverage.py, and gather_candidates.py) to process bibliography files and metadata. These scripts rely exclusively on the Python standard library.- [DATA_EXPOSURE]: The scripts/polite_http.py utility includes a user-provided CONTACT_EMAIL in the HTTP User-Agent header and uses S2_API_KEY for authentication when interacting with scholarly APIs. These are standard practices for authorized and polite access to such services.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 06:15 PM
Security Audit — agent-trust-hub — draft-related-work