Back to skill

Security audit

Arxiv

Security checks for vulnerabilities and agentic risk

Overview

The skill does the advertised ArXiv search work, but it also requires automatic long-term logging of discussed papers without user control.

Install only if you are comfortable with this skill automatically keeping a long-term research log of papers you discuss. Avoid sensitive or proprietary search topics unless you can review, edit, or disable memory/RESEARCH_LOG.md, and treat saved paper titles, abstracts, and summaries as untrusted reference data rather than instructions.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:14
Finding

Untrusted ArXiv Content Is Automatically Written to Persistent Agent Memory

Content
View full analysis
"` to get the XML results. 2. Parse the XML (look for ``, ``, `<summary>`, and `<link title="pdf">`). 3. Present the findings to the user. 4. **MANDATORY**: Append the title, authors, date, and summary of any paper discussed to `memory/RESEARCH_LOG.md`. Use the format: ```markdown ### [YYYY-MM-DD] TITLE_OF_PAPER - **Authors**: Author List - **Link**: ArXiv Link - **Summary**: Brief summary of the paper and its relevance. ``` ``` ### Technical Analysis The Skill retrieves paper metadata and abstracts from ArXiv and can retrieve additional PDF content through `web_fetch`. Titles, author names, abstracts, and PDF text are externally supplied and therefore cannot be assumed to be trusted. The workflow mandates that information derived from every discussed paper be appended to `memory/RESEARCH_LOG.md`. It does not require user confirmation, sanitize instruction-like text, enforce a strict data-only serialization format, or mark stored content as untrusted. Consequently, a malicious ArXiv submission could include text designed to influence an Agent. If the resulting title, author data, or summary preserves that content and the memory file is later loaded as trusted context, the content can persistently affect subsequent sessions. This is an Agent memory-poisoning risk rather than direct local code execution. Exploitation depends on a later component loading the research log into Agent context and failing to maintain a trust boundary between store ...[truncated 1562 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a shell script (scripts/search_arxiv.sh) but does not declare any explicit tool scope such as allowed tools or permissions. This creates an avoidable trust gap: the runtime may grant broader execution capability than users expect, and reviewers cannot easily verify that shell access is limited to the intended ArXiv query operation.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill presents itself as a search-and-summarize tool, but also persists discussed papers to memory/RESEARCH_LOG.md for long-term storage. This is a scope expansion beyond the user-visible purpose, and it can silently retain sensitive research interests, proprietary topics, or investigation history without clear expectation or consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill states that summarized papers are automatically recorded to persistent memory without any user warning or consent mechanism. Silent persistence can expose user interests, internal research priorities, or sensitive topics to later sessions and other workflows that read from shared memory.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow makes persistent logging mandatory for any discussed paper, including title, authors, link, date, and summary, yet gives the user no warning or control. Because the logging is automatic and comprehensive, it can create an audit trail of sensitive research activity that persists beyond the immediate task.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill description says it searches and summarizes ArXiv papers, but the workflow also permits web_fetch on PDF links for deeper extraction. This broadens data access and processing behavior beyond the narrow advertised function, which can increase exposure to untrusted remote content and surprise users about the extent of retrieval performed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script transmits the user-supplied search query to a third-party service (ArXiv) without any user-facing notice or consent mechanism. While this is expected for the skill’s functionality, it is still a real privacy/transparency issue because user input may contain sensitive terms and is sent off-platform.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.