research-lit
Warn
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill employs Python heredocs (`python3
- <<'PY'`) to execute script content generated during runtime, specifically for the paper verification fallback mechanism in SKILL.md.
- [DYNAMIC_EXECUTION]: External Python utilities (such as
arxiv_fetch.py,verify_papers.py, andresearch_wiki.py) are invoked using file paths computed at execution time based on project structure and environment variables. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection. 1. Ingestion points: processes data from local PDFs, Zotero, Obsidian, and multiple web APIs (arXiv, Semantic Scholar, Exa, OpenAlex, Gemini). 2. Boundary markers: no specific delimiters or "ignore embedded instructions" warnings are used for ingested content. 3. Capability inventory: utilizes Bash for command execution, Write for file modifications, and WebFetch for network requests. 4. Sanitization: lacks visible sanitization or validation of external content before interpolation.
- [COMMAND_EXECUTION]: The skill relies heavily on the Bash tool to perform complex coordination of external tools and environment discovery, executing various shell commands to resolve paths and run fetchers.
- [DATA_EXFILTRATION]: The skill reads project-level configuration files (e.g., CLAUDE.md) and scans local directories (papers/, literature/) for content, potentially exposing metadata or internal paths within the user's environment.
Audit Metadata