sci-zotero

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The script zotero.py performs dynamic module loading using importlib.util. Specifically, the _init_shared_env function attempts to locate and execute a Python module named env_config.py from a relative directory path (../_shared/env_config.py). This technique allows the execution of arbitrary code if the target file is modified or if the skill is deployed in an environment where the directory structure can be manipulated.
  • [DATA_EXFILTRATION]: The skill retrieves API keys and user credentials by reading from the file ~/.aut_sci_write/.env. While this is a common practice for secret management in developer tools, it involves accessing a sensitive file path. The skill then transmits these credentials to the Zotero API and interacts with several other external bibliographic services (CrossRef, PubMed, Open Library) to synchronize data.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from multiple external bibliographic APIs and local files, which could serve as a vector for indirect prompt injection if the ingested data contains malicious instructions meant to influence the agent's behavior.
  • Ingestion points: API responses from api.zotero.org, api.crossref.org, openlibrary.org, eutils.ncbi.nlm.nih.gov, and api.unpaywall.org; local text files provided via the crossref command.
  • Boundary markers: No explicit markers or "ignore instructions" warnings are used when processing or displaying data retrieved from these sources.
  • Capability inventory: The script has the capability to perform network GET/POST requests and write files to the disk (temporary downloaded PDFs).
  • Sanitization: The script uses standard JSON parsing and includes basic sanitization for filenames when saving PDF attachments.
  • [EXTERNAL_DOWNLOADS]: The fetch-pdfs command enables the download of PDF files from arbitrary external URLs provided by the Unpaywall API metadata. The skill implements some defensive measures, such as a 100 MB file size limit and checking the Content-Type header to ensure the response is a PDF rather than HTML, which helps mitigate basic server-side request forgery (SSRF) and disk-filling attacks.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 06:16 PM
Security Audit — agent-trust-hub — sci-zotero