Back to skill

Security audit

global-biblio-base

Security checks across malware telemetry and agentic risk

Overview

The skill is a real literature-search integration, but it asks the agent to register users, handle payments, store identifiers, and try broad PDF retrieval methods including anti-hotlink workarounds.

Review this carefully before installing. Use it only if you are comfortable sending your email, search requests, document identifiers, and payment-order details to SmartLib/Alipay flows, and avoid using the automated PDF retrieval path for content where you do not have rights or clear open-access permission. Confirm any paid plan deliberately and verify where downloaded files will be written.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The document explicitly recommends a shell-based curl fallback and, elsewhere in troubleshooting, suggests deploying Chromium CDP to work around publisher anti-hotlinking defenses. That goes beyond normal literature retrieval and normalizes technical circumvention of access controls, creating legal/compliance risk and enabling automated acquisition workflows against publisher restrictions.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill materially expands from literature search into payment orchestration by instructing the agent to create Alipay orders, render payment pages, and poll payment status. That introduces financial transaction handling, extra PII processing (email for billing), and a broader attack surface that is not necessary for core search functionality.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill directs the agent to use many external retrieval channels and even browser automation/CDP to obtain full text beyond the declared SmartLib API scope. This broadens network reach, increases data exfiltration and prompt-injection exposure from third-party sites, and risks policy or rights violations when attempting automated acquisition of publisher content.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The usage guidance includes bulk download workflows and writes papers to local output directories without a clear warning, consent step, or safety constraints. In an agent context, this can lead to unexpected file-system side effects, excessive storage use, and large-scale downloading behavior that the user may not have explicitly approved.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The documentation recommends executing curl via subprocess as a fallback but does not present a clear user-facing warning about invoking an external system command. In agent or hosted environments, subprocess execution expands the trust boundary, increases operational risk, and may violate sandboxing or policy expectations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The README states that first use triggers automatic registration through a gateway without clearly informing the user what data will be sent, what account will be created, or obtaining explicit consent. This creates a privacy and autonomy risk because a user may unknowingly cause account creation and transmission of identifiers or query data to a third-party service.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The README instructs users to initiate payment inside the chat and receive an Alipay payment code without a clear warning that payment orders will be generated and order details shared with a payment provider. This can lead to unexpected financial actions, insufficient consent, and exposure of transaction metadata to external systems.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger list is broad enough to match common writing-assistance requests such as literature reviews or finding supporting citations, which can cause the skill to activate when the user did not clearly request this specific integration. Over-broad activation increases the chance of unnecessary data collection, unintended external calls, and unexpected quota-consuming actions.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The top-level activation summary uses ambiguous wording such as broad '查/找/下载文献' and writing-related scenarios, which makes accidental invocation more likely. In context, unintended activation is more dangerous because the skill also requests email registration and can trigger billable external operations.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The document instructs collection of a user's email address for automatic registration without mentioning consent, retention, purpose limitation, or a privacy notice. In a skill that handles academic searches and downloads across a shared wallet, silent collection of personally identifiable information can lead to privacy-law noncompliance, user deception, and unnecessary exposure if the data is later breached or repurposed.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The document specifies tracking download history using email plus document ID to enforce a 72-hour re-download window, but it does not disclose this tracking or define retention and access controls. Because the skill processes identifiable user behavior tied to reading/downloading literature, this can expose sensitive research interests and create privacy and compliance risk if stored broadly, retained too long, or accessed improperly.

Ssd 4

Medium
Confidence
94% confidence
Finding
The stepwise routing guidance normalizes progressively trying multiple techniques to obtain PDFs from restricted or fragile publisher endpoints, including fallback patterns aimed at overcoming protective behavior. In the context of a literature-download skill, this materially increases the likelihood of policy-violating access, abuse of publisher infrastructure, and misuse by downstream agents at scale.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.