Back to skill

Security audit

Setup Obsidian arXiv Daily

Security checks for vulnerabilities and agentic risk

Overview

This skill installs a disclosed Obsidian arXiv digest and optional Windows scheduled task with user-controlled setup steps and bounded file/network behavior.

Install only if you are comfortable with a daily task that reads arXiv results, writes notes inside the chosen Obsidian Vault, archives old generated paper notes, and may send paper title/author/abstract content to DeepSeek when summaries are enabled and DEEPSEEK_API_KEY is present. Review the scheduled task name and target vault before approving scheduling or replacement.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (14)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
97% confidence
Finding

The skill describes operations that require sensitive capabilities including shell execution, filesystem reads/writes, environment-variable access, and possible network use, but it does not declare any explicit tool scope such as permissions or allowed-tools. This creates an overbroad execution surface where an agent may invoke more capabilities than intended, increasing the risk of unauthorized file modification, credential exposure via environment access, or unsafe command execution during installation and task registration.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The fallback summary text and the DeepSeek prompt both require Chinese output, and the generated markdown sections are also Chinese-only. For a code file, this is a natural-language policy issue because the skill imposes a specific language/locale without offering user opt-in or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/arxiv-daily/scripts/test_arxiv_daily.py (reported line 55)May include surrounding context.

python
class ArxivDailyHelperTests(unittest.TestCase):
    def _read_bytes_after_release(self, path: Path) -> bytes:
        return subprocess.check_output(
            [
                sys.executable,
                "-c",

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/arxiv-daily/scripts/test_arxiv_daily.py (reported line 137)May include surrounding context.

python
except (OSError, NotImplementedError):
                if os.name != "nt":
                    self.fail("Unable to create a directory redirection")
                result = subprocess.run(
                    [
                        "cmd",
                        "/c",

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_install_arxiv_daily.py (reported line 186)May include surrounding context.

python
except (OSError, NotImplementedError):
                if os.name != "nt":
                    self.fail("Unable to create a directory redirection")
                result = subprocess.run(
                    [
                        "cmd",
                        "/c",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This test explicitly requires the summary prompt to request strict Chinese JSON output, and related tests assert Chinese section headings and Chinese summary fields throughout the generated content. That indicates the skill is designed to force a specific language/locale behavior rather than offering a user choice, which matches the locale-policy violation criteria.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · assets/arxiv-daily/scripts/test_arxiv_daily.py (reported line 939)May include surrounding context.

python
ensure_ascii=False,
        ).encode("utf-8")
        config = self.make_config(
            deepseek_base_url="https://api.deepseek.com/",
            request_timeout_seconds=45,
        )
        paper = self.make_paper()

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · assets/arxiv-daily/scripts/test_arxiv_daily.py (reported line 950)May include surrounding context.

python
ensure_ascii=False,
        ).encode("utf-8")
        config = self.make_config(
            deepseek_base_url="https://api.deepseek.com/",
            request_timeout_seconds=45,
        )
        paper = self.make_paper()

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · assets/arxiv-daily/scripts/test_arxiv_daily.py (reported line 1156)May include surrounding context.

python
if os.name != "nt":
            self.skipTest("directory junction fallback is Windows-only")

        result = subprocess.run(
            [
                "cmd",
                "/c",

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The template hardcodes Chinese section headings such as '基本信息', '中文摘要', '关键贡献', and '方法简述', which implies the generated skill output is constrained to Chinese. This is a natural-language locale policy issue because the file does not offer any user language choice or document that the Chinese-only format is intentionally limited to a specific audience or region.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_register_scheduled_task.py (reported line 49)May include surrounding context.

python
wrapper.write_text("exit 0\n", encoding="utf-8")
            task_name = "CodexSkillValidation-DoNotCreate"

            result = subprocess.run(
                [
                    "powershell.exe",
                    "-NoProfile",

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · tests/test_register_scheduled_task.py (reported line 72)May include surrounding context.

python
)

            self.assertEqual(result.returncode, 0, result.stderr or result.stdout)
            verification = subprocess.run(
                [
                    "powershell.exe",
                    "-NoProfile",

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The document title is presented entirely in Chinese ("arXiv 每日论文控制面板"), which indicates a fixed language choice in the skill's natural-language interface. The file does not provide any user opt-in, language selection, or justification that this skill is intended only for a Chinese-language audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown template presents all user-facing headings and labels in Chinese, which imposes a specific language on output. The policy allows locale constraints only when user opt-in is offered or the regional limitation is clearly documented and justified, neither of which appears in this file.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
tests/test_install_arxiv_daily.py:22