sci-zotero
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [DYNAMIC_EXECUTION]: The script
zotero.pyperforms dynamic module loading usingimportlib.util. Specifically, the_init_shared_envfunction attempts to locate and execute a Python module namedenv_config.pyfrom a relative directory path (../_shared/env_config.py). This technique allows the execution of arbitrary code if the target file is modified or if the skill is deployed in an environment where the directory structure can be manipulated. - [DATA_EXFILTRATION]: The skill retrieves API keys and user credentials by reading from the file
~/.aut_sci_write/.env. While this is a common practice for secret management in developer tools, it involves accessing a sensitive file path. The skill then transmits these credentials to the Zotero API and interacts with several other external bibliographic services (CrossRef, PubMed, Open Library) to synchronize data. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from multiple external bibliographic APIs and local files, which could serve as a vector for indirect prompt injection if the ingested data contains malicious instructions meant to influence the agent's behavior.
- Ingestion points: API responses from
api.zotero.org,api.crossref.org,openlibrary.org,eutils.ncbi.nlm.nih.gov, andapi.unpaywall.org; local text files provided via thecrossrefcommand. - Boundary markers: No explicit markers or "ignore instructions" warnings are used when processing or displaying data retrieved from these sources.
- Capability inventory: The script has the capability to perform network GET/POST requests and write files to the disk (temporary downloaded PDFs).
- Sanitization: The script uses standard JSON parsing and includes basic sanitization for filenames when saving PDF attachments.
- [EXTERNAL_DOWNLOADS]: The
fetch-pdfscommand enables the download of PDF files from arbitrary external URLs provided by the Unpaywall API metadata. The skill implements some defensive measures, such as a 100 MB file size limit and checking theContent-Typeheader to ensure the response is a PDF rather than HTML, which helps mitigate basic server-side request forgery (SSRF) and disk-filling attacks.
Audit Metadata