academic-mcp-tooling
Warn
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides ready-to-use commands in
references/external-skill-recommendations.mdto install multiple third-party skills from unverified GitHub repositories vianpx. These include repositories from users such asobra,existential-birds,davila7,agents365-ai,fuzhiyu,bahayonghang, andllllllllama. - [EXTERNAL_DOWNLOADS]: The
references/mcp-catalog.mdfile recommends the installation of various MCP servers from third-party sources includingblazickjp,akapet00,cyanheads,eric-tramel,YounesBensafia, andafrise. - [COMMAND_EXECUTION]: The skill's workflow and documentation encourage the execution of shell commands (specifically
npx) to add capabilities and install external software packages. - [EXTERNAL_DOWNLOADS]: The skill fetches configuration and supplementary tools from the
anthropics/skillsrepository, which is a well-known and trusted source. - [EXTERNAL_DOWNLOADS]: The skill references resources from the author's own repository (
VincenzoImp/academic-research-skills), representing intended vendor functionality. - [DATA_EXFILTRATION]: While the skill interacts with sensitive environments like Overleaf (tokens) and Zotero, it incorporates safety guidelines in
references/repository-contract.mdspecifically prohibiting the inclusion of API keys, cookies, or session data in generated configuration snippets.
Audit Metadata