alphaxiv
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted paper data from external sources and uses it in downstream tasks.
- Ingestion points: Fetches paper overviews and markdown from
alphaxiv.organd LaTeX source archives fromarxiv.org(SKILL.md, Steps 2-4). - Boundary markers: The instructions do not define any delimiters or safety warnings for the agent when processing the fetched text.
- Capability inventory: The skill has access to
Bash(*),Read,Write, andGlobtools, enabling shell execution and file system modifications. - Sanitization: There is no mention of sanitizing or escaping the content retrieved from AlphaXiv before processing it or passing it to other tools.
- [COMMAND_EXECUTION]: The skill executes a bash block that incorporates data fetched from the internet.
- Evidence: Step 6 (Research Wiki Ingest) instructs the agent to run a shell command:
python3 "$WIKI_SCRIPT" ingest_paper ... --thesis "<one-line thesis from the Tier 1 overview>". - Risk: The
<one-line thesis>is derived directly from the external AlphaXiv overview. If the content of a paper's AlphaXiv overview contains shell metacharacters, it could lead to command injection when the agent executes the bash block. - [EXTERNAL_DOWNLOADS]: The skill performs network operations to retrieve paper content from established academic domains.
- Evidence: Uses
curlto download markdown fromalphaxiv.organd.tar.gzsource files fromarxiv.org.
Audit Metadata