Back to skill

Security audit

pubmed-verifier

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed citation-verification skill that scans user-selected reference files, contacts academic registries, and writes reports/cache data in ways that fit its purpose.

Install only if you are comfortable sending citation identifiers and claimed metadata from the selected documents to PubMed/NCBI, Europe PMC, Crossref, and arXiv. Use --no-cache for one-off sensitive checks, choose output/export paths carefully because they write files, and avoid pointing --source at broad private directories unless you intend them to be scanned for references.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (18)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill describes capabilities that include reading files, writing reports/cache data, using environment variables, and making network requests, but it does not declare a restrictive tool scope such as explicit permissions or allowed tools. That creates an authorization ambiguity where an agent framework may grant broader access than users expect, increasing the risk of unintended file access, outbound requests, or leakage of API-key/contact data through implicit tool use.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger guidance is broad enough to auto-invoke on generic requests like checking references, validating DOIs, or auditing citations, potentially causing the skill to run without clear user intent or before safer/manual workflows are chosen. Because this skill can read project files and perform outbound network lookups, over-broad triggering can expose local document contents or citation metadata unnecessarily and surprise users with side effects like report generation or cache writes.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 353)May include surrounding context.

md
## Security & behavior declaration

- Single-run CLI: scan, verify, write the report, exit. No daemons, no
  background jobs, nothing downloaded or installed at runtime (pure standard
  library, zero dependencies).
- Network access is limited to these official academic registries, always

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The manifest describes a reference-checking and citation-verification tool centered on verifying PMIDs, DOIs, and related metadata. This section documents a 'Deep Research Workflow (Systematic PubMed Search)' for keyword search, result harvesting, and abstract retrieval, which goes beyond verification into general literature discovery and research assistance.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/verify_pmids.py (reported line 111)May include surrounding context.

python
return "/".join(parts[:3]) if len(parts) > 2 else url


def _api_get(url: str, max_retries: int = 3, timeout=None) -> bytes:
    """HTTP GET hardened for the field: UA rotation on 403/406, Retry-After
    compliance on 429, per-host circuit breaker.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/verify_pmids.py (reported line 441)May include surrounding context.

python
return "/".join(parts[:3]) if len(parts) > 2 else url


def _api_get(url: str, max_retries: int = 3, timeout=None) -> bytes:
    """HTTP GET hardened for the field: UA rotation on 403/406, Retry-After
    compliance on 429, per-host circuit breaker.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

This Python file contains multiple hard-coded Chinese-only user-facing messages, beginning with the circuit-breaker error text here and repeated throughout CLI output and generated reports. For a general-purpose verifier with no documented locale restriction or language selection, forcing a specific language in user-visible output violates the language/locale choice policy.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · scripts/verify_pmids.py (reported line 169)May include surrounding context.

python
time.sleep(2 ** attempt)
    if transport:
        _HOST_FAILS[hk] += 1
    if last_err is None:  # e.g. max_retries=0 — never raise None
        raise RuntimeError(f"no attempts made for {url}")
    raise last_err

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/api_examples.md (reported line 93)May include surrounding context.

md
def fetch_doi_metadata(doi: str) -> dict:
    """Fetch metadata from Crossref API by DOI. With --mailto set, requests
    join the Crossref polite pool (?mailto=) for more generous rate limits."""
    url = f"https://api.crossref.org/works/{urllib.parse.quote(doi, safe='')}"
    if _OPTS["mailto"]:
        url += f"?mailto={urllib.parse.quote(_OPTS['mailto'])}"
    try:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/verify_pmids.py (reported line 344)May include surrounding context.

python
def fetch_doi_metadata(doi: str) -> dict:
    """Fetch metadata from Crossref API by DOI. With --mailto set, requests
    join the Crossref polite pool (?mailto=) for more generous rate limits."""
    url = f"https://api.crossref.org/works/{urllib.parse.quote(doi, safe='')}"
    if _OPTS["mailto"]:
        url += f"?mailto={urllib.parse.quote(_OPTS['mailto'])}"
    try:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/verify_pmids.py (reported line 448)May include surrounding context.

python
def fetch_doi_metadata(doi: str) -> dict:
    """Fetch metadata from Crossref API by DOI. With --mailto set, requests
    join the Crossref polite pool (?mailto=) for more generous rate limits."""
    url = f"https://api.crossref.org/works/{urllib.parse.quote(doi, safe='')}"
    if _OPTS["mailto"]:
        url += f"?mailto={urllib.parse.quote(_OPTS['mailto'])}"
    try:

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/verify_pmids.py (reported line 2914)May include surrounding context.

python
def fetch_doi_metadata(doi: str) -> dict:
    """Fetch metadata from Crossref API by DOI. With --mailto set, requests
    join the Crossref polite pool (?mailto=) for more generous rate limits."""
    url = f"https://api.crossref.org/works/{urllib.parse.quote(doi, safe='')}"
    if _OPTS["mailto"]:
        url += f"?mailto={urllib.parse.quote(_OPTS['mailto'])}"
    try:

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The HTML report embeds Chinese footer text directly, which means every generated report includes a forced locale regardless of user preference. Because this tool otherwise appears intended for broad use and does not expose a language opt-in, this is a natural-language locale policy issue rather than a code-security bug.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This manifest file explicitly declares triggers, so SQP-1 applies. Several phrases such as "check citations", "reference check", "validate references", and especially "AI hallucination detection" are broad enough to match common user requests without clearly limiting activation to PubMed/academic-reference verification, and there are no exclusion conditions or negative examples.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The markdown advertises --export-bibtex, --export-audit, and --export-csv as writing files, but it does not mention any caution about creating or potentially overwriting output paths. Because this is a markdown file, missing user-facing warnings about data-affecting behavior are in scope when the skill description omits them.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill's stated purpose is verifying citations against PubMed/Crossref/arXiv and producing audit reports. Adding GitHub/SkillHub promotional links and 'Star / bookmark' calls-to-action in generated deliverables is not required for verification and is unrelated to the declared auditing function.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The Markdown report appends GitHub/SkillHub links and a request to 'Star / bookmark if you find it useful'. This is a non-verification capability that introduces outbound references in output artifacts without being part of the manifest's citation-checking purpose.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

The HTML output includes branded footer links to GitHub and SkillHub plus a promotional 'Star / 收藏' call to action. This behavior is outside the core function of verifying references and is not justified by the manifest's stated purpose.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.