Scientific Article PDF Generator

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a straightforward remote paper-generation API integration, with the main risk being that drafts and research details are sent to Paper.EvoWeb.ai.

Install only if you are comfortable sending paper drafts, product facts, URLs, and research parameters to Paper.EvoWeb.ai for remote processing. Do not submit secrets, unpublished research, personal data, or proprietary material unless you have permission and understand the provider's data handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill instructs the assistant to send user-provided article drafts, product facts, URLs, and optionally perform external research via a third-party API, but it does not clearly warn users that their content will leave the local environment and be processed remotely. This creates a privacy and data-governance risk, especially because scientific drafts, white papers, or product data may contain confidential, proprietary, regulated, or unpublished information.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal