cli-anything-zotero
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides a CLI harness (
cli-anything-zotero) that executes local commands to interact with the Zotero desktop application, including runtime inspection and database operations. - [PROMPT_INJECTION]: The skill functions as a data ingestion source for the AI agent, fetching user-controlled content from Zotero (notes, item metadata, and attachments) to build LLM context. This creates a surface for indirect prompt injection if the Zotero library contains malicious instructions.
- Ingestion points: Local Zotero SQLite database and Zotero Local API.
- Boundary markers: Not explicitly defined in the instructions.
- Capability inventory: Local file/database reads, Local API requests, and experimental local write operations.
- Sanitization: No evidence of input validation or content filtering is provided in the skill documentation.
Audit Metadata