Search SOP

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [DATA_EXFILTRATION]: Accesses local reference manager databases, specifically Zotero and EndNote files (e.g., zotero.sqlite), to import existing bibliographies.
  • [EXTERNAL_DOWNLOADS]: Interfaces with numerous academic API services including CrossRef, OpenAlex, Europe PMC, and the developer-specific Wentor API for literature discovery.
  • [COMMAND_EXECUTION]: Employs browser automation (RPA) for interacting with search engines like Google Scholar and CNKI, governed by specific limits on snapshots and pagination to ensure efficiency.
  • [PROMPT_INJECTION]: Processes untrusted external content such as paper abstracts and search results, creating a surface for indirect prompt injection.
  • Ingestion points: External data from APIs and browser snapshots.
  • Boundary markers: Lacks explicit delimiters for separating external metadata from instructions.
  • Capability inventory: Can modify local libraries and interact with web browsers.
  • Sanitization: No specific content validation or filtering is described for incoming data.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 01:20 AM