sci-download

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The config.py file uses importlib.util to load a shared configuration module from a relative directory. This is a standard modular architecture pattern for related scientific tools to share common environment logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains an attack surface for indirect prompt injection through the ingestion of external data. 1. Ingestion points: Data is fetched from academic APIs and HTML scrapers in arxiv_download.py, ieee_download.py, pubmed_download.py, semantic_scholar_download.py, and cnki_download.py. 2. Boundary markers: None identified. 3. Capability inventory: The skill has network access and file-write capabilities but no shell execution sinks. 4. Sanitization: Standard XML, JSON, and HTML parsing is used.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to download scientific PDF documents from trusted publishers and university portals as part of its primary function.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:24 AM
Security Audit — agent-trust-hub — sci-download