academic-mcp-tooling

Warn

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides ready-to-use commands in references/external-skill-recommendations.md to install multiple third-party skills from unverified GitHub repositories via npx. These include repositories from users such as obra, existential-birds, davila7, agents365-ai, fuzhiyu, bahayonghang, and llllllllama.
  • [EXTERNAL_DOWNLOADS]: The references/mcp-catalog.md file recommends the installation of various MCP servers from third-party sources including blazickjp, akapet00, cyanheads, eric-tramel, YounesBensafia, and afrise.
  • [COMMAND_EXECUTION]: The skill's workflow and documentation encourage the execution of shell commands (specifically npx) to add capabilities and install external software packages.
  • [EXTERNAL_DOWNLOADS]: The skill fetches configuration and supplementary tools from the anthropics/skills repository, which is a well-known and trusted source.
  • [EXTERNAL_DOWNLOADS]: The skill references resources from the author's own repository (VincenzoImp/academic-research-skills), representing intended vendor functionality.
  • [DATA_EXFILTRATION]: While the skill interacts with sensitive environments like Overleaf (tokens) and Zotero, it incorporates safety guidelines in references/repository-contract.md specifically prohibiting the inclusion of API keys, cookies, or session data in generated configuration snippets.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 20, 2026, 09:06 AM