sci-extract

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests scientific papers and metadata from external academic databases such as Crossref, OpenAlex, and PubMed to generate research insights. While this constitutes an attack surface for indirect prompt injection, the skill mitigates this by enforcing a rigid analysis framework (e.g., the Heilmeier catechism) and using explicit markdown delimiters to separate paper content from agent instructions. The ingestion of academic papers is the intended primary purpose of the skill.\n- [SAFE]: The toolkit implements several security best practices. The HTTP session manager in harvester/http.py includes a _scrub function to ensure that API keys and institutional tokens are never leaked into logs or error messages. Additionally, harvester/jats.py provides XXE and 'billion laughs' protection by stripping DOCTYPE declarations from publisher XML before parsing. All external network requests target well-known academic services and cloud providers.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:16 PM
Security Audit — agent-trust-hub — sci-extract