semantic-scholar

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the Semantic Scholar API, including paper titles, abstracts, and TLDRs, which are then used in subsequent shell commands.
  • Ingestion points: Data enters via the Semantic Scholar API response in Step 2 and Step 3.
  • Boundary markers: No explicit delimiters or instructions are provided to the model to ignore potentially malicious instructions embedded in paper metadata.
  • Capability inventory: The skill has Bash and Write capabilities, used for running fetcher scripts and updating a research wiki.
  • Sanitization: There is no evidence of sanitization or escaping of paper metadata before it is interpolated into shell commands (e.g., in Step 7).
  • [COMMAND_EXECUTION]: User-supplied search queries and extracted paper metadata are interpolated directly into shell commands, creating a potential command injection surface.
  • Evidence: In Step 2, user arguments are passed to a Python script via Bash: python3 "$S2_FETCHER" search "QUERY". If the "QUERY" (derived from $ARGUMENTS) contains shell metacharacters, it could lead to arbitrary command execution.
  • Evidence: In Step 7, paper metadata is passed to a wiki script: python3 "$WIKI_SCRIPT" ingest_paper ... --title "<title>". If a paper title contains shell metacharacters and the execution environment does not handle quoting strictly, it could trigger malicious commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:48 PM
Security Audit — agent-trust-hub — semantic-scholar