Back to skill

Security audit

ArXiv Watcher

Security checks for vulnerabilities and agentic risk

Overview

This ArXiv research helper is purpose-aligned and disclosed, with a privacy-relevant local research log users should be aware of before use.

Install only if you are comfortable with discussed papers being saved locally in memory/RESEARCH_LOG.md for long-term tracking. Avoid using it for confidential research topics unless you are prepared to review or delete that log yourself.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill documents use of a shell script (scripts/search_arxiv.sh) but does not declare any tool scope or permissions boundary. This creates an authorization and transparency gap: an agent may invoke shell capabilities not clearly surfaced to reviewers or users, increasing the chance of unintended command execution or overbroad tool access.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The stated purpose of the skill is searching and summarizing ArXiv papers, but it also performs persistent local logging to memory/RESEARCH_LOG.md. This is a scope expansion beyond user-visible functionality and can cause silent retention of user interests, research topics, or sensitive queries without informed consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Automatic saving to memory/RESEARCH_LOG.md is presented as a capability without warning that the action creates persistent local records. Users may reasonably expect transient summarization, so undisclosed retention can expose sensitive research interests or accumulate data that later becomes accessible to other skills or users.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The workflow mandates automatic appends to a memory file for any discussed paper, yet this write behavior is not part of the declared search-and-summary purpose. Hidden side effects like persistent file modification increase privacy risk and make the skill behave beyond its advertised scope.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Marking the append to memory as MANDATORY without a persistence warning normalizes silent file writes as part of routine operation. This removes user choice and increases the risk of unwanted data retention, especially for confidential or proprietary research topics.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
74% confidence
Finding

All example invocations are written in Spanish, which suggests a language expectation, but the skill does not explicitly state that users may choose their preferred language. This can be a locale/language policy issue when a skill appears to default to a specific language without opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.