arxiv-watcher

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted research paper abstracts from the ArXiv API, which could be used as a vector for indirect prompt injection.
  • Ingestion points: XML output from scripts/search_arxiv.sh containing paper summaries and titles.
  • Boundary markers: The instructions do not define any delimiters or system-level warnings to distinguish paper content from agent instructions during parsing.
  • Capability inventory: The skill is capable of writing to memory/RESEARCH_LOG.md and fetching external content via web_fetch on PDF links.
  • Sanitization: No sanitization or escaping mechanisms are mentioned for the external summary text.
  • [EXTERNAL_DOWNLOADS]: Fetches research data from the official ArXiv API (export.arxiv.org) using curl within a script.
  • [COMMAND_EXECUTION]: Executes the local bash script scripts/search_arxiv.sh to interact with the ArXiv API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:41 AM
Security Audit — agent-trust-hub — arxiv-watcher