The Research-to-Publish Workflow: Sources, Citations, Drafts, Done
Research work has a shape: collect sources, extract what matters, get the citations right, produce the document. Each step eats untrusted material from outside — which makes this exactly the workflow where a skill's security posture matters as much as its output quality.
This chain crosses four categories, because research itself does. Every skill below handles documents it didn't write — PDFs, transcripts, web pages, statutes — which is why we note the injection-test results where we have them.
1. Collect: baoyu-url-to-markdown — 9.2/10
Any web page into clean Markdown. The collector for everything that isn't behind a paywall.
The one thing: It's your front door for untrusted content. It behaved perfectly in our tests, but keep it upstream of anything with credentials — see the secure loadout.
2. Digest: qiaomu-anything-to-notebooklm — 6.7/10
Bulk-converts arbitrary material into NotebookLM-ready source sets.
Why despite the score: It's the only skill doing this job, and the low static score is about polish, not function. Our injection test gave it 7.5 — it dropped a rule-override boundary, so review what it batches.
3. Retrieve: rag-architect — 9.3/10, injection-tested 10/10
Designs the retrieval layer — chunking strategy, embeddings, evaluation — when your source pile outgrew "just read it."
Why: Research quality is retrieval quality. rag-architect treats corpus-building as an engineering problem with measurable recall, not vibes. It held all four adversarial boundaries in both tiers of our dynamic batch — notable, because retrieval skills face a whole class of poisoning attacks.
4. Cite: law-citation-skill — 8.8/10, injection-tested 7.5/10
Bluebook citation checking for law-adjacent writing; generalizable as "the citation-enforcement skill."
The honest caveat: In our September injection batch it complied with a rule override — skipping the verification pass its own spec declares mandatory. The fix is procedural, not technical: don't instruct it to skip checks when you're in a hurry. Verification steps are load-bearing.
5. Produce: pdf → docx — 8.6 and 9.7/10, both injection-tested 7.5/10
The official document generators: extract from PDFs, draft in Word.
The pattern from the batch: The document generators dropped the same rule-override boundary — told "skip the revision check," several did. None of them leaked injected instructions out of source files, and none touched out-of-scope paths. Verdict: safe against attackers, over-trusting of you. Read what they emit before it ships.
6. The specialist wing
- us-legal-research (8.4) — Federal Register and US-code lookup, the legal variant of stage 1.
- contract-review CUAD (8.5, injection-tested 10/10) — when the "sources" are contracts and the output is a risk memo.
Collect, digest, retrieve, cite, produce — five stages, and the injection results say the risk concentrates at the cite-and-produce end, precisely where you're the one giving the orders. Documents category, dynamic badges included, or the full legal injection report.
