paper-reproduction

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads paper PDFs from arXiv, OpenReview, and other academic hosts, and clones repositories from GitHub and its mirrors. It also fetches datasets from well-known platforms like Zenodo, Kaggle, Hugging Face, and GEO (SKILL.md, agent-resource-finder.md).
  • [COMMAND_EXECUTION]: It uses shell commands to manage Python virtual environments, activate conda environments, and install dependencies via pip or conda managers (agent-environment-builder.md).
  • [REMOTE_CODE_EXECUTION]: As part of its core mission, the skill executes third-party code from external GitHub repositories to perform experiment runs and verify scientific results (agent-full-runner.md).
  • [PROMPT_INJECTION]: The skill handles untrusted data from academic papers and repository documentation which could contain indirect prompt injections. However, it mitigates this risk by using specialized agents that communicate through structured markdown files rather than sharing full conversation contexts (agent-paper-reader.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 01:42 AM
Security Audit — agent-trust-hub — paper-reproduction