Back to skill

Security audit

Arxiv Watcher

Security checks across malware telemetry and agentic risk

Overview

This skill fetches public arXiv paper metadata and maintains a local starred-paper list, with no evidence of hidden or destructive behavior.

Reasonable to install for arXiv browsing and bookmarking. Be aware that it contacts arXiv, displays external paper text, and saves starred paper metadata locally; use explicit arXiv prompts if you want to avoid accidental activation for generic paper-search requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger list includes broad natural-language phrases such as "check arxiv," "new papers," and "latest papers on," which can match common user requests beyond the intended explicit skill invocation. This can cause unintended activation of the skill, leading to surprising network access, irrelevant actions, or interference with other more appropriate skills handling general research or news queries.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.