research-arxiv-scout
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external research paper abstracts and community comments (e.g., from arXiv, Hugging Face, and alphaXiv). This content is used to score papers and generate automated entries for a shared ledger file (pay-trigger-ledger.tsv). Maliciously crafted abstracts could potentially influence the agent's behavior or lead to the insertion of deceptive information into project databases.
- Ingestion points: export.arxiv.org/api/query, rss.arxiv.org, huggingface.co/papers, and alphaxiv.org (referenced in SKILL.md and data/sources.json).
- Boundary markers: The skill lacks explicit instructions or delimiters to isolate untrusted abstract content from the agent's primary directive.
- Capability inventory: The skill possesses the ability to write to local and relative file paths, specifically ../../research-review-mining/assets/pay-trigger-ledger.tsv, and recommends updates to 02_sources-*.json files.
- Sanitization: No explicit sanitization or instruction-filtering logic is present for processing external text.
- [EXTERNAL_DOWNLOADS]: The skill connects to established research and discovery services, including arXiv, Semantic Scholar, and OpenAlex. These network operations are necessary for the skill's function and target well-known, reputable services.
- [COMMAND_EXECUTION]: The skill utilizes a local Python script (scripts/generate_arxiv_scout_queries.py) to resolve search parameters from config.yaml. The documentation also provides examples of using curl for interacting with the arXiv OAI-PMH interface. These are routine operations for data retrieval and configuration management.
Audit Metadata