Back to skill

Security audit

sciverse academic retrieval

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Sciverse academic retrieval connector that uses a user-provided API token to fetch paper metadata, text, and figures from Sciverse.

Install only if you are comfortable providing a Sciverse API token to this skill. It will send search queries, document IDs, and resource names to Sciverse endpoints to retrieve academic metadata, text snippets, citation relations, and images; some error text and schema descriptions are Chinese-only.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

Several user-facing field descriptions are presented only in Chinese while other parts of the manifest are in English. This creates a forced mixed-language experience without explicit opt-in or documentation that the skill is intended for a Chinese-speaking audience.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script emits operational error messages exclusively in Chinese when required configuration is missing. This is a natural-language locale constraint in a code file, and there is no indication that users can choose another language or that the skill is intentionally region-specific.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

Comments and the user-facing error message are written only in Chinese, which imposes a specific language without offering any user opt-in or alternative. This matches the language/locale policy violation category because the file does not provide a language choice or document a justified locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The user-facing error strings and comments are written in Chinese, and the runtime validation messages at L16 and L26 provide no alternative language or opt-in. This creates a language/locale policy issue because the skill imposes a specific language on users without offering a choice or documenting a justified region-specific constraint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

The script fetches a remote resource and emits its binary contents as base64 JSON, but the file contains no user-facing log, prompt, or explanatory comment disclosing that network data will be retrieved and returned. Because this is a code file and the operation transmits/handles remote data, the absence of any explicit warning in the code meets the missing-user-warning criterion.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The code emits a user-visible error message only in Chinese: "必须提供 doc_id 字段。" This imposes a specific language on users without any opt-in or documented locale justification, which matches the natural-language policy violation criteria.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/_common.mjs:12