Back to skill

Security audit

scholar-search-zh

Security checks across malware telemetry and agentic risk

Overview

The skill is framed as scholarly search, but its bundled client also exposes broader web search, URL extraction, and model-query features that are not clearly disclosed in the user-facing instructions.

Review before installing. Use it only if you are comfortable sending search queries, prompts, and any supplied URLs to AISA and related backend services. Do not use private URLs, credentials, unpublished research, or sensitive internal material with this skill unless you have independently accepted that provider data handling.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Context-Inappropriate Capability

Medium
Confidence
86% confidence
Finding
The extract command allows users to submit arbitrary URLs to an external service, causing third-party retrieval and transmission of potentially sensitive targets and content. In a scholar-search skill, this broad fetch capability exceeds expected scope and can be misused to disclose private URLs, internal resources, or user-supplied sensitive links to the vendor API.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
User queries and URL extraction inputs are transmitted to an external API without any explicit notice, consent mechanism, minimization, or redaction. In a research skill, users may paste unpublished ideas, internal URLs, or sensitive data, making undisclosed third-party transmission a meaningful privacy and confidentiality risk.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.