Back to skill

Security audit

Cjg Paper Fact Checker

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed paper fact-checking workflow, but users should be aware that it can involve meeting transcripts, speaker attribution, external checking services, and local usage logging.

Install only if you are comfortable using it in meeting contexts where papers, references, transcripts, speaker identity, and user-provided figures may be analyzed. Confirm meeting consent before using transcript or recording features, and say the documented opt-out phrase if you do not want local method-tag logging.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
81% confidence
Finding
The skill advertises image-plagiarism checking in a paper/PDF-triggered workflow, but only later narrows the image step to figures proactively provided by the user. This mismatch can cause users to reasonably believe the agent will inspect images contained in shared PDFs or meeting materials, creating a transparency and consent gap around what content may be analyzed.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Collecting presenter identity, meeting transcript context, and encouraging recording for later review goes beyond the minimum data needed to fact-check a paper. In a meeting setting, this can expose participant-linked reading activity and discussion history, increasing privacy risk and creating unnecessary surveillance-style data linkage.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The default-on '进化燃料' telemetry records post-use method tags persistently even though it is not essential to the core fact-checking function. Because the skill operates in a meeting context, even seemingly limited telemetry can still reveal sensitive behavioral patterns about what users analyze and when, beyond reasonable expectations.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
Automatic post-use recording is enabled by default, but the privacy implications are disclosed only inside the body of the skill rather than prominently in user-facing metadata or activation flow. Users may invoke the skill expecting transient analysis, not ongoing local logging, so the consent is not sufficiently informed.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill describes automatic triggering from Tencent Meeting transcription plus participant attribution, but does not provide a clear, prominent warning about the privacy consequences for everyone in the meeting. This can lead to covert or unexpected analysis of shared content and identity-linked activity in a collaborative setting.

Ssd 3

Medium
Confidence
88% confidence
Finding
Default-on natural-language usage logging in a meeting-derived workflow risks capturing sensitive context about papers discussed, user behavior, and participant-linked activity, even if the skill claims to store only method tags. In practice, such telemetry can drift beyond user expectations and become a source of unintended disclosure or profiling.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.