ANNE Library Downloader

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it asks for institutional library credentials while its advertised automation is incomplete and under-scoped.

Review carefully before installing. Do not provide institutional credentials unless you are comfortable exposing them to this runtime and the publisher clarifies credential handling. Expect incomplete automation, missing helper scripts, and external DOI lookups that may reveal research interests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill explicitly instructs users to export institutional library credentials and advertises automated authentication across multiple academic platforms, but it provides no warning about credential handling, storage, transmission, or the risk of account misuse. In this context, users may expose sensitive institutional credentials to scripts or automation they do not fully trust, increasing the chance of credential theft, unauthorized access, or policy violations.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The function sends user-supplied book title and author data to the external Crossref API without any explicit consent, warning, or privacy disclosure. In a library/downloader context, these queries may reveal a user's academic interests, institutional work, or sensitive research topics to a third party.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal