sci-search
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
sci_search.pycontains an_init_shared_envfunction that usesimportlib.utilto dynamically load and execute a Python module from a relative path (../_shared/env_config.py). Loading and executing code from computed paths at runtime is a risk factor as it can be exploited if an attacker can write to sibling directories. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple external academic APIs (arXiv, PubMed, WoS, Springer, Scopus, Semantic Scholar, OpenAlex).
- Ingestion points: Data is fetched in the
searchmethods of various fetcher classes insci_search.py. - Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the fetched paper titles or abstracts.
- Capability inventory: The skill has network access (
urllib.request) and file writing capabilities (PaperLibrarycache). - Sanitization: The script performs basic string cleaning but does not sanitize potential prompt injection patterns within the retrieved paper content.
- [COMMAND_EXECUTION]: The
SKILL.mddocumentation provides examples of executing the Python script via the command line with user-controlled arguments, which are then parsed and used to construct API queries.
Audit Metadata