zenodo-skill
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands including git, awk, and sed to identify updates from the vendor repository.
- [REMOTE_CODE_EXECUTION]: The skill facilitates updates by executing git pull from its origin source upon user confirmation, allowing for remote modification of skill content.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests research metadata from Zenodo API endpoints which may contain malicious instructions. Ingestion points: Zenodo search results and deposition metadata in SKILL.md and references/search.md. Boundary markers: Absent. Capability inventory: curl, git, and jq. Sanitization: Absent.
Audit Metadata