Back to skill

Security audit

ArXiv Watcher

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent ArXiv search helper, but it requires automatic long-term logging of every discussed paper without user consent or containment.

Review this skill before installing if you do not want research topics or paper summaries saved automatically. The main risk is not theft or destructive behavior, but mandatory persistent logging of your research activity and remote paper content without an opt-in step.

Vulnerability Patterns
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T02 · Agent Memory Poisoning

Warning
Location
SKILL.md:20
Finding

Untrusted ArXiv Metadata Is Mandatorily Written to Persistent Agent Memory

Content
View full analysis
"` to get the XML results. 2. Parse the XML (look for ``, ``, `<summary>`, and `<link title="pdf">`). 3. Present the findings to the user. 4. **MANDATORY**: Append the title, authors, date, and summary of any paper discussed to `memory/RESEARCH_LOG.md`. Use the format: ```markdown ### [YYYY-MM-DD] TITLE_OF_PAPER - **Authors**: Author List - **Link**: ArXiv Link - **Summary**: Brief summary of the paper and its relevance. ``` ``` The capability is also described at line 10: ```markdown - **Save to Memory**: Automatically record summarized papers to `memory/RESEARCH_LOG.md` for long-term tracking. ``` ### Technical Analysis The workflow requires the agent to persist titles, author names, links, and summaries derived from remotely supplied ArXiv XML. These fields are untrusted external content. The instructions do not require validation, escaping, provenance labeling, instruction-content filtering, or user authorization before writing the data to long-term memory. An attacker able to publish or influence metadata for a paper could place prompt-like instructions in its title, author data, or abstract. When a matching paper is discussed, the agent is explicitly required to copy or summarize that content into `memory/RESEARCH_LOG.md`. If this log is later loaded into an agent context, the stored text could be mistaken for trusted instructions rather than treated exclusively as quoted research data. The issue does not itself prove that arbitrary commands will be executed. Successful behavioral influence depends on whether and how the surrounding agent system loads the research log in future sessions. Nevertheless, the mandatory, unfiltered persistence creates the prerequisite f ...[truncated 1320 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/search_arxiv.sh:3
Finding

Unvalidated Inputs Are Interpolated Directly into the ArXiv Request URL

Content
View full analysis
Remediation
View remediation
50 )); then printf 'COUNT must be an integer from 1 through 50\n' >&2 exit 2 fi curl --silent --show-error --fail-with-body \ --location --globoff \ --connect-timeout 10 --max-time 30 \ --get 'https://export.arxiv.org/api/query' \ --data-urlencode "search_query=all:$QUERY" \ --data-urlencode 'start=0' \ --data-urlencode "max_results=$COUNT" \ --data-urlencode 'sortBy=submittedDate' \ --data-urlencode 'sortOrder=descending' ``` ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding

The skill invokes a shell script (scripts/search_arxiv.sh) but does not declare any tool scope or allowed-tools boundary. This creates an authorization gap where an agent may run shell-capable actions without explicit restriction, increasing the chance of unintended command execution or broader tool access than the skill appears to require.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill states that summarized papers should be automatically saved to memory/RESEARCH_LOG.md for long-term tracking without any user consent step. Automatic persistence can store user interests, research topics, or sensitive investigation themes beyond the current session, creating avoidable privacy and data-retention risk.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow marks file writes to memory/RESEARCH_LOG.md as 'MANDATORY' for any discussed paper, which removes agent discretion and bypasses a privacy warning or consent check. In context, an ArXiv research skill may be used for confidential competitive research, personal interests, or sensitive topics, so mandatory logging makes the privacy issue more dangerous rather than less.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

All provided invocation examples are in Spanish, which suggests a language-specific interaction pattern, but the skill does not say that language is optional or user-selectable. Under the policy, skills should not implicitly force a specific language or locale without opt-in or justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.