arxiv-watcher
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted research paper abstracts from the ArXiv API, which could be used as a vector for indirect prompt injection.
- Ingestion points: XML output from
scripts/search_arxiv.shcontaining paper summaries and titles. - Boundary markers: The instructions do not define any delimiters or system-level warnings to distinguish paper content from agent instructions during parsing.
- Capability inventory: The skill is capable of writing to
memory/RESEARCH_LOG.mdand fetching external content viaweb_fetchon PDF links. - Sanitization: No sanitization or escaping mechanisms are mentioned for the external summary text.
- [EXTERNAL_DOWNLOADS]: Fetches research data from the official ArXiv API (
export.arxiv.org) usingcurlwithin a script. - [COMMAND_EXECUTION]: Executes the local bash script
scripts/search_arxiv.shto interact with the ArXiv API.
Audit Metadata