Back to skill

Security audit

Research Daily Push

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a coherent research-paper summary tool with user-directed scheduling and no hidden install-time or destructive behavior.

Install only if you want arXiv literature reports for specified research topics. Review any cron job before adding it, and provide push-channel targets or messaging credentials only if you are comfortable sharing research topics, paper links, and generated summaries through those services.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Vague Triggers

Medium
Confidence
75% confidence
Finding
The cron example sends a very generic message, '推送今日最新文献', which could accidentally invoke this skill whenever a scheduler or automation layer forwards that text without additional scoping. Because the skill performs outbound retrieval and push delivery, unreliable activation increases the chance of unintended network activity and unsolicited notifications, especially in multi-skill agent environments.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README documents outbound push channels and targets but does not warn that content and identifiers may be transmitted to third-party services such as Feishu, WeChat, or email providers. In a research workflow, summaries, user interests, and recipient identifiers can reveal sensitive topics or personal data, so missing disclosure and controls create privacy and data-handling risk.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The cron message "推送今日最新文献" is a generic natural-language phrase that could plausibly overlap with ordinary user requests or other skills, making unintended scheduled invocation more likely. In a compatibility-layer skill that forwards users to another entry point, this ambiguity increases the chance of the wrong automation target being triggered or of accidental task execution without clear user intent boundaries.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The description says the skill will automatically retrieve the latest arXiv papers and generate structured summaries, but it does not clearly state when it activates, what user consent is required, or what boundaries govern the automated behavior. Ambiguous activation scope can cause unintended execution, surprise network access, or unsolicited content delivery, which is a genuine security and safety concern even though the manifest alone does not show direct code execution abuse.

Natural-Language Policy Violations

Medium
Confidence
90% confidence
Finding
The description hardcodes Chinese-language behavior (e.g., a Chinese-only skill description and implied output style) without indicating that language selection follows user preference. Forcing a language without opt-in can mislead users, reduce transparency, and cause incorrect or inaccessible output, especially in automated summary workflows where users may rely on precise comprehension.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.