aminer-free-academic
Pass
Audited by Gen Agent Trust Hub on Apr 28, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
curlto interact with AMiner's API gateway atdatacenter.aminer.cn. This is used to perform searches for papers, scholars, organizations, venues, and patents. - [DATA_EXFILTRATION]: The skill transmits the user's
AMINER_API_KEYto the official AMiner domain for authentication. This is the intended and documented behavior for the service. - [PROMPT_INJECTION]: The skill processes external data from API responses, such as paper abstracts and scholar interests, which enters the agent context. This presents a potential surface for indirect prompt injection; however, the skill lacks boundary markers or sanitization for this data. Despite this common risk factor, no specific malicious instructions were detected within the skill's logic or documentation.
Audit Metadata