sci-extract
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests scientific papers and metadata from external academic databases such as Crossref, OpenAlex, and PubMed to generate research insights. While this constitutes an attack surface for indirect prompt injection, the skill mitigates this by enforcing a rigid analysis framework (e.g., the Heilmeier catechism) and using explicit markdown delimiters to separate paper content from agent instructions. The ingestion of academic papers is the intended primary purpose of the skill.\n- [SAFE]: The toolkit implements several security best practices. The HTTP session manager in
harvester/http.pyincludes a_scrubfunction to ensure that API keys and institutional tokens are never leaked into logs or error messages. Additionally,harvester/jats.pyprovides XXE and 'billion laughs' protection by stripping DOCTYPE declarations from publisher XML before parsing. All external network requests target well-known academic services and cloud providers.
Audit Metadata