openalex
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands to resolve the file path of a Python helper script (
openalex_fetch.py). The resolution logic usesgit,awk, andcatto read local environment configurations such as.aris/installed-skills.txtand~/.aris/repoto dynamically determine where the search tool is located. - [INDIRECT_PROMPT_INJECTION]: The skill processes and presents untrusted metadata from the OpenAlex API, such as paper abstracts and titles, which are not sanitized and could contain instructions designed to influence agent behavior.
- Ingestion points: Metadata fields including
abstract,title, andauthorsretrieved in Step 4 are displayed to the user and processed by the agent in Step 5. - Boundary markers: There are no delimiters or specific instructions to treat the API-provided data as untrusted.
- Capability inventory: The skill is configured with
Bash(*),Read, andWritetool access and performs shell executions. - Sanitization: The skill does not mention any validation, filtering, or escaping of the content fetched from the API.
Audit Metadata