academic-research-mapper
Warn
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: MEDIUMPERSISTENCEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PERSISTENCE]: The skill provides explicit instructions for users to persist the
TINYFISH_API_KEYby appending export commands to shell initialization files (~/.bashrcor~/.zshrc) and by modifying local application settings (~/.claude/settings.local.json). These actions ensure the credential persists across sessions and environment reloads. - [EXTERNAL_DOWNLOADS]: Recommends the installation of the
@tiny-fish/clipackage from the NPM registry to provide the necessary terminal commands for the skill to function. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data fetched from external sources including arXiv, Semantic Scholar, and Google Scholar using browser automation.
- Ingestion points: Data is fetched as JSON search results from multiple external web domains.
- Boundary markers: No explicit boundary markers or instructions to ignore embedded malicious prompts are included in the agent's extraction goals.
- Capability inventory: The skill uses the TinyFish CLI to perform network operations and shell redirection to store results in temporary files.
- Sanitization: There is no evidence of sanitization or validation performed on the external content before it is synthesized into the final landscape report.
- [COMMAND_EXECUTION]: Executes several shell commands to check for the presence of the required CLI tool, verify its version, and check authentication status.
Audit Metadata