doi-bibtex
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: Indirect prompt injection surface identified (Category 8). The skill retrieves arbitrary text content from the external DOI registry and integrates it into the agent's context to be processed and written to local files.\n
- Ingestion points: Raw BibTeX output from
scripts/doi2bib.sh, fetched from the externaldoi.orgservice.\n - Boundary markers: None identified. No delimiters or 'ignore' instructions are used to isolate the untrusted content.\n
- Capability inventory: The skill has the capability to search the filesystem for bibliography files and append content to them.\n
- Sanitization: No validation or sanitization is performed on the bibliographic data before it is presented to the user or written to disk.\n- [EXTERNAL_DOWNLOADS]: The skill fetches citation metadata from the well-known
doi.orgservice viacurlinscripts/doi2bib.sh.
Audit Metadata