literature-search — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited literature-search (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill is not a loop — it is the literature-retrieval dependency several loops use for paper discovery and novelty checks. It bundles tools/lit_search.py (a stdlib-only entrypoint) and the tools/lit/ package: Semantic Scholar (S2) for semantic search + snippets + the citation graph and arXiv for full-text reads (the keyless core), plus optional OpenAlex, Perplexity Sonar (ask), and bgpt.pro (bgpt) when their keys are set. Every subcommand prints JSON; on a terminal failure it prints {"error","fallback"} and exits non-zero so the caller degrades to its built-in WebSearch/WebFetch. No installs, Python ≥3.9.
A consuming loop resolves these once at setup and reuses them:
cp -r loops/* ~/.claude/skills/ itsits as a sibling of the calling loop, e.g. ~/.claude/skills/literature-search/ (adjust per host). If it cannot be resolved, the caller falls back to WebSearch/WebFetch — depending on it never hard-breaks a loop, it only enriches it.
<lit_skill_dir>/tools/lit_search.py.The entrypoint is executable and carries a #!/usr/bin/env python3 shebang, so it runs directly with no python3 prefix. To reuse a cache across calls, append --cache-dir <sandbox_root>/literature/.cache after the subcommand (a per-subcommand flag, not global).
<lit_py> <lit_skill_dir>/tools/lit_search.py, with <lit_py> = python3 (any ≥3.9 interpreter).
Invoke `<lit>` as one command — keep it a single shell token. In particular zsh does not word-split unquoted variables, so storing the two-wordpython3 .../lit_search.pyin a variable and calling$VARtries to exec one long (nonexistent) filename. Use the executable single-token form above, call the script path directly, or split explicitly (${=VAR}in zsh).
| Subcommand | Use | ||||
|---|---|---|---|---|---|
| `<lit> search "<q>" [--year 2020-] [--min-citations N] [--limit N] [--source s2\ | openalex\ | both] [--sort relevance\ | citations\ | recent]` | semantic discovery — related papers (titles, TLDR, abstract, citations, arxiv_id). Defaults to --source s2 (relevance); add openalex/both to widen discovery |
<lit> snippet "<q>" [--limit N] | full-text passage search — pinpoint a verbatim fact/number without reading a paper | ||||
| `<lit> cite <paperId> --direction references\ | citations\ | recommend` | walk the citation graph (backward / forward / "more like this") | ||
| `<lit> fulltext <arxivId> [--mode auto\ | latex\ | pdf]` | deep-read one paper's methods/results (HTML > LaTeX > PDF) | ||
| `<lit> ask "<question>" [--model sonar\ | sonar-pro\ | sonar-reasoning]` | Perplexity Sonar synthesis — a cited high-level answer (needs OPENROUTER_API_KEY; else use WebSearch) | ||
<lit> bgpt "<q>" [--num N] [--days-back N] | bgpt.pro structured experimental-result/limitations extraction (free for 50 results, then BGPT_API_KEY) | ||||
<lit> keys [--init] | report which API keys are present (booleans only); --init writes/extends keys.env |
The S2 + arXiv core (search/snippet/cite/fulltext) needs no keys. The optional extras (search --source openalex|both, ask, bgpt) widen discovery and synthesis when their keys are set.
This skill is the canonical home for the project's key convention (it is the installed code that implements it). Keys live in one gitignored `keys.env` at the project root (the nearest .git ancestor of the working dir, else the CWD), shared by every skill in the project.
KEY=VALUE lines; # comments; blank lines ignored; 0600 perms.export).keys.env themselves; skills read onlypresence as booleans, never values.
Onboarding flow: <lit> keys (report what's present) → <lit> keys --init (create/append slots, append-only, never overwrites; prints the path) → user opens keys.env and pastes the keys they want (in-session: ! $EDITOR ./keys.env) → <lit> keys again, then proceed. Never block on keys.
search/snippet/cite.--source openalex|both.ask (Perplexity Sonar); without it ask is disabled.bgpt beyond the free tier.python3.../ escapes, no docs/ links.{"error","fallback"} and exit non-zerorather than raising, so callers degrade cleanly.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.