openalex

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to resolve the file path of a Python helper script (openalex_fetch.py). The resolution logic uses git, awk, and cat to read local environment configurations such as .aris/installed-skills.txt and ~/.aris/repo to dynamically determine where the search tool is located.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes and presents untrusted metadata from the OpenAlex API, such as paper abstracts and titles, which are not sanitized and could contain instructions designed to influence agent behavior.
  • Ingestion points: Metadata fields including abstract, title, and authors retrieved in Step 4 are displayed to the user and processed by the agent in Step 5.
  • Boundary markers: There are no delimiters or specific instructions to treat the API-provided data as untrusted.
  • Capability inventory: The skill is configured with Bash(*), Read, and Write tool access and performs shell executions.
  • Sanitization: The skill does not mention any validation, filtering, or escaping of the content fetched from the API.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:49 PM
Security Audit — agent-trust-hub — openalex