cluade-scientific-writer-wrapper

Security checks across malware telemetry and agentic risk

Overview

This skill is a transparent wrapper for a scientific writing Python package, with disclosed API-key use and file outputs that match its stated purpose.

Install only if you trust the scientific-writer package and publisher. Use dedicated API keys, keep .env out of version control, and avoid submitting confidential research, proprietary data, or patient-identifiable content unless the provider terms and privacy controls are acceptable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
87% confidence
Finding
The documentation states that outputs are saved to `writing_outputs/` but does not warn users that running the skill will create files on disk or clarify whether existing files may be overwritten. While this is not inherently malicious, silent file creation can surprise users, cause unintended persistence of sensitive scientific content, and in some implementations may lead to accidental overwrite of prior work.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal