citation-finder
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it fetches and processes content from external academic databases.
- Ingestion points: Metadata is retrieved from CrossRef, Semantic Scholar, Baidu Scholar, and CNKI using search scripts.
- Boundary markers: There are no specified delimiters or instructions for the agent to ignore potentially malicious content embedded within paper titles or metadata.
- Capability inventory: The skill includes scripts for searching and formatting data, which are then output by the agent to the user.
- Sanitization: The instructions do not specify any sanitization or validation steps for the external data before it is presented to the agent's context.
Audit Metadata