sci-search

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script sci_search.py contains an _init_shared_env function that uses importlib.util to dynamically load and execute a Python module from a relative path (../_shared/env_config.py). Loading and executing code from computed paths at runtime is a risk factor as it can be exploited if an attacker can write to sibling directories.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple external academic APIs (arXiv, PubMed, WoS, Springer, Scopus, Semantic Scholar, OpenAlex).
  • Ingestion points: Data is fetched in the search methods of various fetcher classes in sci_search.py.
  • Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the fetched paper titles or abstracts.
  • Capability inventory: The skill has network access (urllib.request) and file writing capabilities (PaperLibrary cache).
  • Sanitization: The script performs basic string cleaning but does not sanitize potential prompt injection patterns within the retrieved paper content.
  • [COMMAND_EXECUTION]: The SKILL.md documentation provides examples of executing the Python script via the command line with user-controlled arguments, which are then parsed and used to construct API queries.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 06:15 PM
Security Audit — agent-trust-hub — sci-search