NYC
skills/smithery/ai/arxiv-search/Gen Agent Trust Hub

arxiv-search

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS] (LOW): The skill documentation recommends installing the arxiv Python package from PyPI. While this is a standard package for this utility, it constitutes an external dependency.
  • [PROMPT_INJECTION] (LOW): The skill is vulnerable to indirect prompt injection because it processes and displays abstracts from the arXiv repository. An attacker could theoretically publish a paper with an abstract containing malicious instructions.
  • Ingestion points: Data returned from arXiv API (titles and summaries).
  • Boundary markers: None identified in documentation or script usage.
  • Capability inventory: Execution of local Python scripts via shell.
  • Sanitization: No explicit sanitization of API content mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 05:37 PM