citation-skills

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for installing well-known research tools and plugins from official repositories, including GitHub, NPM, and PyPI. All external resources point to legitimate academic or technology services.- [COMMAND_EXECUTION]: Includes Python and shell snippets for interacting with academic APIs and command-line utilities like Papis and Zotero. These examples follow security best practices, such as recommending environment variables for sensitive API keys.- [DATA_EXFILTRATION]: Network activity is restricted to trusted academic and technology service domains such as zotero.org, crossref.org, openalex.org, and mendeley.com. No suspicious or unauthorized data transmission patterns were identified.- [PROMPT_INJECTION]: While the skill involves processing external bibliographic data, it uses structured formats (JSON, BibTeX) and well-defined API schemas, which significantly reduces the risk of indirect prompt injection compared to unstructured data ingestion.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 12:17 PM