pubmed-database

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONOBFUSCATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill enables the agent to fetch external research content such as abstracts and citations from the PubMed API. This represents a potential surface for indirect prompt injection if the fetched data contains malicious instructions aimed at overriding agent behavior. * Ingestion points: PubMed article abstracts and metadata retrieved through the E-utilities REST API as described in SKILL.md. * Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded in the fetched article text. * Capability inventory: The skill demonstrates network access using the Python requests library to interact with external endpoints. * Sanitization: No sanitization or content validation steps are documented for the fetched scientific literature.
  • [OBFUSCATION]: The technical support email address in the support section is written in reverse (vog.hin.mln.ibcn@seitilitue for eutilities@ncbi.nlm.nih.gov). While likely intended as an anti-spam measure for web crawlers, this is a form of obfuscated content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:29 AM
Security Audit — agent-trust-hub — pubmed-database