Back to skill

Security audit

arXiv

Security checks across malware telemetry and agentic risk

Overview

This is a read-focused arXiv skill whose setup steps deserve attention but are disclosed and gated, with no evidence of hidden data access or harmful behavior.

Install only if you are comfortable using the OOMOL oo CLI for arXiv lookups. Do not let an agent install the CLI or run OOMOL login unless you intentionally approve that setup step; routine arXiv search and paper-fetch actions are read-only.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill's safety section frames untagged arXiv actions as safe reads, but later instructs the agent to perform environment-changing commands such as installing software and authenticating with an external service. This creates a misleading safety boundary: an agent could perform privileged side effects without user confirmation because they are presented as setup rather than as risky operations.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
For a skill whose stated purpose is searching and reading arXiv data, bundling software installation and account-authentication instructions expands its authority beyond the minimum necessary scope. That increases the chance an agent will modify the host environment or initiate account flows unrelated to the user's immediate arXiv request.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The instruction to use this skill for ANY arXiv request is overly broad and can override safer routing or direct, lower-risk handling. Broad trigger language increases the chance the agent invokes this skill in contexts where its extra setup behaviors or shell access are unnecessary.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.