skills/yy/claude-scholar/doi-bibtex/Gen Agent Trust Hub

doi-bibtex

Pass

Audited by Gen Agent Trust Hub on May 6, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: Indirect prompt injection surface identified (Category 8). The skill retrieves arbitrary text content from the external DOI registry and integrates it into the agent's context to be processed and written to local files.\n
  • Ingestion points: Raw BibTeX output from scripts/doi2bib.sh, fetched from the external doi.org service.\n
  • Boundary markers: None identified. No delimiters or 'ignore' instructions are used to isolate the untrusted content.\n
  • Capability inventory: The skill has the capability to search the filesystem for bibliography files and append content to them.\n
  • Sanitization: No validation or sanitization is performed on the bibliographic data before it is presented to the user or written to disk.\n- [EXTERNAL_DOWNLOADS]: The skill fetches citation metadata from the well-known doi.org service via curl in scripts/doi2bib.sh.
Audit Metadata
Risk Level
SAFE
Analyzed
May 6, 2026, 02:29 AM
Security Audit — agent-trust-hub — doi-bibtex