pubmed-database
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [OBFUSCATION]: A contact email address is provided in reversed format ('vog.hin.mln.ibcn@seitilitue' for 'eutilities@ncbi.nlm.nih.gov') in SKILL.md and references/api_reference.md. This technique is typically used to prevent automated scraping but matches patterns of content obfuscation.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface.
- Ingestion points: The agent is instructed to fetch and process article abstracts, titles, and metadata from the NCBI E-utilities API.
- Boundary markers: There are no instructions providing delimiters or warnings to ignore potentially malicious instructions embedded within the retrieved scientific literature.
- Capability inventory: The skill enables the agent to perform HTTP requests and process the resulting text/XML/JSON data.
- Sanitization: No sanitization or validation logic is defined to check for or strip instructions from the external data before it is incorporated into the agent's context.
Audit Metadata