research-lit

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill employs Python heredocs (`python3
  • <<'PY'`) to execute script content generated during runtime, specifically for the paper verification fallback mechanism in SKILL.md.
  • [DYNAMIC_EXECUTION]: External Python utilities (such as arxiv_fetch.py, verify_papers.py, and research_wiki.py) are invoked using file paths computed at execution time based on project structure and environment variables.
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection. 1. Ingestion points: processes data from local PDFs, Zotero, Obsidian, and multiple web APIs (arXiv, Semantic Scholar, Exa, OpenAlex, Gemini). 2. Boundary markers: no specific delimiters or "ignore embedded instructions" warnings are used for ingested content. 3. Capability inventory: utilizes Bash for command execution, Write for file modifications, and WebFetch for network requests. 4. Sanitization: lacks visible sanitization or validation of external content before interpolation.
  • [COMMAND_EXECUTION]: The skill relies heavily on the Bash tool to perform complex coordination of external tools and environment discovery, executing various shell commands to resolve paths and run fetchers.
  • [DATA_EXFILTRATION]: The skill reads project-level configuration files (e.g., CLAUDE.md) and scans local directories (papers/, literature/) for content, potentially exposing metadata or internal paths within the user's environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 06:49 PM
Security Audit — agent-trust-hub — research-lit