ArXiv Watcher for Music Research

Security checks across malware telemetry and agentic risk

Overview

The skill is a disclosed ArXiv research helper with limited local logging and no artifact-backed evidence of command execution abuse or hidden behavior.

Reasonable to install if you want an ArXiv research workflow that creates local audit files. Review the output paths before use, avoid user-supplied domain names that contain path traversal like ../, and treat the search script as an ArXiv API helper rather than a hardened general-purpose URL builder.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill states it will automatically create directories and write logs/JSON files into the local workspace without warning or requesting user approval. Silent file writes can overwrite user data, leak sensitive research context into persistent storage, or enable unintended persistence/audit artifacts in shared environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal