Security audit
Hfpclawer Citation Audit
Security checks for vulnerabilities and agentic risk
Overview
This skill is a straightforward citation-checking helper that discloses its local and academic API lookup workflow, with no hidden execution or persistence found.
Install if you are comfortable using hfpclawer and with citation titles, arXiv IDs, or batch reference contents being queried against Semantic Scholar or OpenAlex. Use the documented local source mode for confidential or unpublished reference lists, and review the external hfpclawer package before using it in sensitive workflows.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
