academic-scientific-research

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown instructions and configuration metadata. There are no Python scripts, JavaScript files, or shell commands included in the package.
  • [SAFE]: The skill defines a required input for 'TAVILY_API_KEY'. This is a standard and secure way to handle authentication by requesting the user to provide their own key at runtime, rather than hardcoding credentials.
  • [SAFE]: All external links in the metadata (homepage and source repository) point to the official domains of the author, 'tavily', and are consistent with the skill's stated purpose.
  • [PROMPT_INJECTION]: As a research tool that ingests external data (academic papers, PubMed, journals), the skill has an inherent surface for indirect prompt injection. Malicious instructions could theoretically be embedded in the content being summarized.
  • Ingestion points: External websites, PDFs, and scholarly sources accessed via search/extract tools.
  • Boundary markers: The skill uses a structured 'Output Template' which acts as a form of boundary, but no explicit 'ignore instructions' markers are present.
  • Capability inventory: No local execution capabilities (subprocess, eval, file-write) are present in this skill.
  • Sanitization: None specified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 02:12 PM
Security Audit — agent-trust-hub — academic-scientific-research