cli-anything-zotero

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides a CLI harness (cli-anything-zotero) that executes local commands to interact with the Zotero desktop application, including runtime inspection and database operations.
  • [PROMPT_INJECTION]: The skill functions as a data ingestion source for the AI agent, fetching user-controlled content from Zotero (notes, item metadata, and attachments) to build LLM context. This creates a surface for indirect prompt injection if the Zotero library contains malicious instructions.
  • Ingestion points: Local Zotero SQLite database and Zotero Local API.
  • Boundary markers: Not explicitly defined in the instructions.
  • Capability inventory: Local file/database reads, Local API requests, and experimental local write operations.
  • Sanitization: No evidence of input validation or content filtering is provided in the skill documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 01:53 PM
Security Audit — agent-trust-hub — cli-anything-zotero