academic-research-mapper

Warn

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: MEDIUMPERSISTENCEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PERSISTENCE]: The skill provides explicit instructions for users to persist the TINYFISH_API_KEY by appending export commands to shell initialization files (~/.bashrc or ~/.zshrc) and by modifying local application settings (~/.claude/settings.local.json). These actions ensure the credential persists across sessions and environment reloads.
  • [EXTERNAL_DOWNLOADS]: Recommends the installation of the @tiny-fish/cli package from the NPM registry to provide the necessary terminal commands for the skill to function.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data fetched from external sources including arXiv, Semantic Scholar, and Google Scholar using browser automation.
  • Ingestion points: Data is fetched as JSON search results from multiple external web domains.
  • Boundary markers: No explicit boundary markers or instructions to ignore embedded malicious prompts are included in the agent's extraction goals.
  • Capability inventory: The skill uses the TinyFish CLI to perform network operations and shell redirection to store results in temporary files.
  • Sanitization: There is no evidence of sanitization or validation performed on the external content before it is synthesized into the final landscape report.
  • [COMMAND_EXECUTION]: Executes several shell commands to check for the presence of the required CLI tool, verify its version, and check authentication status.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 20, 2026, 08:21 AM
Security Audit — agent-trust-hub — academic-research-mapper