semantic-scholar
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from the Semantic Scholar API, including paper titles, abstracts, and TLDRs, which are then used in subsequent shell commands.
- Ingestion points: Data enters via the Semantic Scholar API response in Step 2 and Step 3.
- Boundary markers: No explicit delimiters or instructions are provided to the model to ignore potentially malicious instructions embedded in paper metadata.
- Capability inventory: The skill has
BashandWritecapabilities, used for running fetcher scripts and updating a research wiki. - Sanitization: There is no evidence of sanitization or escaping of paper metadata before it is interpolated into shell commands (e.g., in Step 7).
- [COMMAND_EXECUTION]: User-supplied search queries and extracted paper metadata are interpolated directly into shell commands, creating a potential command injection surface.
- Evidence: In Step 2, user arguments are passed to a Python script via Bash:
python3 "$S2_FETCHER" search "QUERY". If the "QUERY" (derived from$ARGUMENTS) contains shell metacharacters, it could lead to arbitrary command execution. - Evidence: In Step 7, paper metadata is passed to a wiki script:
python3 "$WIKI_SCRIPT" ingest_paper ... --title "<title>". If a paper title contains shell metacharacters and the execution environment does not handle quoting strictly, it could trigger malicious commands.
Audit Metadata