systematic-review-prisma

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The references/mcp-catalog.md file provides a list of third-party Model Context Protocol (MCP) servers available on GitHub (e.g., blazickjp/arxiv-mcp-server, akapet00/semantic-scholar-mcp, cyanheads/openalex-mcp-server) to assist with academic research tasks. These are documented as recommended candidates for manual installation and are not executed automatically by the skill.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external academic data (e.g., search results, paper metadata, and PDFs).
  • Ingestion points: Raw search results are exported to sources/metadata/ and screening decisions are recorded in sota/screening-decisions.csv.
  • Boundary markers: The instructions do not define specific delimiters for separating ingested external content from system instructions.
  • Capability inventory: The skill primarily utilizes file system operations (read/write) and interactions with configured MCP servers for search and retrieval.
  • Sanitization: There is no explicit mention of sanitization for the metadata or text extracted from external sources.
  • [DATA_EXFILTRATION]: While the skill interacts with external APIs (arXiv, Semantic Scholar, etc.) via MCP servers, these operations are standard for the intended research purpose. The documentation explicitly advises users to be aware of risks associated with certain tools and to record configurations in a local setup file.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 09:06 AM