Back to skill

Security audit

Nature Paper Workflow 论文生产链

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed academic-paper workflow router with no direct execution, credential access, network use, or file-writing behavior in the inspected artifact.

Installers should understand this skill mainly steers paper-workflow requests into other installed skills. Review the permissions of those sub-skills before using stages that may download papers, create project files, analyze data, or call external services, and specify your target venue when it is not a Nature-family journal.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (11)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad user intents such as '帮我写论文', '帮我投稿', and '论文全流程', which can match high-level everyday requests rather than a clear request to invoke a router. That can cause unintended activation of this top-level skill, overriding more specific or safer task routing and steering users into a preset workflow they did not explicitly choose.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill states a default assumption of a Nature-series journal workflow when the venue is not specified, which imposes a specific publication path without user opt-in. This can misroute users into unsuitable guidance, bias downstream sub-skill selection, and produce recommendations inconsistent with the user's actual target venue or constraints.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger set for literature-survey routing includes broad phrases such as '综述' and '找文献', which can plausibly appear in ordinary academic conversations without the user intending to invoke this specific workflow stage. In a top-level router, overly permissive matching can cause unintended skill activation, misroute user requests, and expose downstream capabilities or context that were not explicitly requested.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The drafting phase uses highly generic triggers like '起草', which are underspecified and likely to overlap with many unrelated writing requests. Because this skill is a global router, ambiguous activation can incorrectly hand off users into a paper-writing pipeline they did not intend to use.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger list includes the single word 'reviewer', which is too broad and may match ordinary discussion about peer review, job roles, or document comments. In a routing manifest, such broad matching increases the chance of accidental activation of the reviewer-simulation workflow.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The polishing phase contains generic triggers such as 'polishing' and '润色', which are common in many writing contexts beyond academic manuscript preparation. This can lead the router to activate the Nature-oriented polishing workflow for unrelated requests, reducing reliability and potentially causing unnecessary delegation.

Vague Triggers

Medium
Confidence
81% confidence
Finding
Triggers such as '投稿前' or '预检' are generic enough to overlap with many ordinary checking or preparation requests. In a top-level workflow router, this ambiguity can cause unintentional entry into the submission-audit stage, especially when the user is merely discussing preparation rather than requesting routing.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The PPT-conversion derived scenario includes broad phrases like '组会汇报', which may occur in general lab or presentation discussions unrelated to converting a paper into slides. Because derived workflows are optional and context-sensitive, broad triggers here raise the risk of incorrect routing more than narrowly scoped phase names would.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger phrase "新论文" is broad and can appear in ordinary conversation about a new paper rather than an explicit request to initialize a project. In a top-level router, this can cause unintended delegation to `paper-bootstrap`, leading the agent into the wrong workflow stage and producing actions or guidance the user did not intend.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The phrase "综述" is highly overloaded in academic contexts and may refer to writing a review article, summarizing a paper, or performing literature research. Because this skill is a router, such ambiguity can misroute users to literature-search subskills when they may actually want writing, reading, or editing support.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger "润色" is a generic editing term that can match many unrelated requests, from casual text polishing to academic manuscript editing. In this workflow router, that increases the chance of false activation of `nature-polishing` and related subskills, which can bypass more appropriate routing or user confirmation.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.