Back to skill

Security audit

学术论文检索小助手

Security checks for vulnerabilities and agentic risk

Overview

The skill matches its academic-search purpose, but it needs review because it handles an optional API key unsafely and installs unpinned Python dependencies.

Review before installing. Use an isolated virtual environment, pin or lock dependencies first, avoid passing --semantic-api-key on the command line, and only use PDF download or output paths you explicitly intend to write to. The skill does not appear malicious, but its credential and dependency practices should be fixed before broad or shared use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/research.py:561
Finding

Semantic Scholar API Key Exposed Through Command-Line Arguments

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
scripts/requirements.txt:4
Finding

Unpinned and Unhashed Third-Party Dependencies

Content
View full analysis
=2.31.0 urllib3>=2.0.0 # Semantic Scholar(用于 S2 API 调用) semanticscholar>=0.8.0 # arXiv 预印本搜索 arxiv>=2.0.0 # PubMed 生物医学文献 biopython>=1.81 # HTTP 重试 urllib3>=1.26.0 ``` The documented installation command resolves and installs these dependencies dynamically: ```bash pip install -r scripts/requirements.txt ``` ### Technical Analysis All dependencies use open-ended minimum-version constraints rather than reviewed exact versions. No cryptographic hashes or lockfile are provided. Consequently, the effective code installed by users can change after the Skill itself has been audited. If a future permitted package release or one of its transitive dependencies is compromised, the package may execute attacker-controlled code during installation or when imported by `scripts/research.py`. Python dependencies normally execute with the privileges of the user running `pip` or the Skill. The file also declares `urllib3` twice with different minimum constraints. Although the resolver will normally combine these constraints, the duplication makes dependency policy less clear and can contribute to inconsistent maintenance. The reviewed package names correspond to expected libraries and there is no evidence of dependency confusion, typosquatting, or an intentionally malicious package in the current project. The issue is the absence of reproducibility and integrity controls. ### Attack Path 1. A user follows the documented `pip install -r scripts/requirements.txt` instruction. 2. The package resolver selects any available release satisfying the open-ended constraints, including releases published after this audit. 3. A permitted direct or transitive de ...[truncated 989 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (30)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 54)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 83)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 101)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 104)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 107)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 110)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
python scripts/research.py multi "transformer attention" -n 10

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
pip install -r scripts/requirements.txt

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill advertises capabilities that imply network access and local file creation/output, but it does not declare any explicit tool scope or permission boundaries. This can cause an agent runtime to invoke broader-than-expected tools for searches, downloads, or file writes, increasing the chance of unintended data access or local side effects.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger scope is broad enough to activate on generic academic-help requests, not just explicit literature search tasks. Overbroad activation can cause the agent to make unnecessary network requests, retrieve external content, or offer file-producing actions in contexts where the user did not intend to invoke this skill.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The visible natural-language instructions and descriptions are entirely in Chinese, with no indication that users may choose another language or that the skill is intentionally limited to a Chinese-speaking audience. This can constitute a language/locale policy issue when no opt-in or justification is provided.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The line explicitly advertises "全中文输出" (Chinese-only output). Per the policy, forcing a specific language without offering user choice or documenting a justified locale constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The module docstring, CLI description, help text, status messages, and formatted output are written exclusively in Chinese, which imposes a specific language on users. The file does not offer an opt-in language selection or explain that the skill is intentionally limited to a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill is described as a literature search and citation helper, but it also supports downloading remote PDF files and saving them locally. This expands the capability from metadata retrieval into file acquisition and local persistence, which can create security and governance risks such as unwanted storage of untrusted files, policy bypass, or abuse for bulk content collection.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code performs direct retrieval of URLs from external metadata and writes the response body to local files. Even though the filenames are mostly fixed-format, this still introduces a file write/download primitive unrelated to the core citation-search use case and increases risk from storing malicious or unexpected content from third-party URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
90% confidence
Finding

The markdown documents PDF download and output file behavior but does not clearly warn that the skill may create local files or write to user-specified paths. This can lead to unexpected disk writes, clutter, or accidental overwriting when an agent follows the documented behavior automatically.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
98% confidence
Finding

L057 states that the skill does not read or store the S2_API_KEY environment variable and that the key is only passed via CLI arguments. Later, L189 says S2_API_KEY is configured by the user in ~/.bashrc, which directly conflicts with the earlier instruction and creates intent/documentation divergence.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
77% confidence
Finding

This requirements file contains natural-language comments in Chinese identifying the skill as a Chinese-language assistant. Under the stated policy, forcing a specific language without user opt-in can be a locale/language policy concern, and there is no indication here of optional language selection or region-specific justification.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
92% confidence
Finding

Using a lower-bound-only dependency specifier for requests allows future installs to pull in any newer release, making builds non-reproducible and potentially introducing vulnerable or breaking versions from the supply chain. In a skill that performs network retrieval from multiple external sources, HTTP client security and consistent behavior are important, so unpinned versions increase exposure.

Content

Scanner excerpt · scripts/requirements.txt (reported line 4)May include surrounding context.

text
# 学术论文检索小助手 - Python 依赖

# 核心检索
requests>=2.31.0
urllib3>=2.0.0

# Semantic Scholar(用于 S2 API 调用)

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
88% confidence
Finding

The finding is valid because requests has known advisories and the manifest does not pin a specific version, so there is no assurance that deployments avoid affected releases. In a network-heavy academic search skill, HTTP client flaws can impact credential handling, request verification, redirects, or transport security when talking to external services.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
95% confidence
Finding

An unpinned urllib3 version permits installation of arbitrary future compatible releases, increasing the risk of supply-chain instability and accidental inclusion of versions with security regressions. Because this skill depends on external HTTP APIs, urllib3 sits in a sensitive path for TLS, redirects, proxies, and response handling.

Content

Scanner excerpt · scripts/requirements.txt (reported line 5)May include surrounding context.

text
# 核心检索
requests>=2.31.0
urllib3>=2.0.0

# Semantic Scholar(用于 S2 API 调用)
semanticscholar>=0.8.0

Unverifiable Dependency: urllib3 has 16 known advisory(ies) (CVE-2025-66471 (urllib3 streaming API improperly handles highly compressed data); CVE-2024-37891 (urllib3's Proxy-Authorization request header isn't stripped during cross-origin ); CVE-2026-21441 (Decompression-bomb safeguards bypassed when following HTTP redirects (streaming ) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
91% confidence
Finding

This is a real supply-chain risk: urllib3 has multiple advisories and the file does not establish an exact safe version, so installations may resolve to affected releases. Given the skill’s reliance on outbound HTTP and possible redirect/proxy/compression handling, vulnerable urllib3 versions could materially affect confidentiality or availability.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
86% confidence
Finding

Leaving semanticscholar unpinned reduces build reproducibility and can introduce unexpected API behavior or vulnerable transitive dependencies over time. While this library is less security-critical than the core HTTP stack, it still processes remote data and therefore should be version-controlled.

Content

Scanner excerpt · scripts/requirements.txt (reported line 8)May include surrounding context.

text
urllib3>=2.0.0

# Semantic Scholar(用于 S2 API 调用)
semanticscholar>=0.8.0

# arXiv 预印本搜索
arxiv>=2.0.0

Static analysis

No suspicious patterns detected.