Back to skill

Security audit

ars-pipeline-orchestrator

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate academic workflow orchestrator, but it can keep detailed collaboration records and optionally send selected material to external verification providers if enabled.

Before installing, be comfortable with a workflow that reads full manuscripts and conversation history, keeps audit/resume artifacts, and may generate a shareable process record with verbatim user quotes. Leave cross-model verification disabled unless you trust the named provider and are willing to send the stated manuscript or dialogue excerpts.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The skill includes a collaboration observer that evaluates and scores the user's behavior across checkpoints and Stage 6, which introduces user profiling beyond the core task of paper orchestration. In this context, that is risky because the same file also specifies process-record generation and retention, creating a plausible path for unnecessary behavioral surveillance, consent gaps, and overcollection of interaction metadata.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Stage 6 goes beyond orchestration into collaboration-quality scoring and AI self-reflection reporting, which can capture and formalize sensitive interaction history unrelated to delivering the paper itself. Because this pipeline explicitly creates a 'process record' of human-AI collaboration, the added evaluative reporting increases privacy and secondary-use risk if users are not clearly warned and allowed to decline before data is compiled.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The agent is defined as an advisory-only observer of collaboration behavior, but the appended 'Universal Academic Integrity Rules' expand its authority into content verification, OCR handling, and claim validation. This scope creep can cause the orchestrator or downstream consumers to treat the observer as a quasi-gating integrity checker, creating inconsistent behavior and potentially exposing more raw user content to unnecessary processing.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The file explicitly says this agent is not an integrity check and does not verify paper content, but later gives binding instructions to verify evidence, avoid unsupported claims, perform OCR-based reading, and recheck computations. These contradictory directives create a dangerous authority-confusion flaw: an agent or orchestrator may follow the stronger 'binding' rules and let this observer influence content validation, pipeline behavior, or user trust outside its intended non-blocking role.

Intent-Code Divergence

High
Confidence
98% confidence
Finding
The exception flow explicitly allows the user to 'Continue to next stage' after Stage 2.5 or 4.5 exceed three failed integrity-verification rounds, even though the state machine elsewhere declares those integrity checks mandatory and non-skippable. In this pipeline, integrity reports are prerequisites for review/finalization, so this contradiction can be exploited to bypass the core safety gate and advance unverifiable or fabricated academic content through the workflow.

Intent-Code Divergence

Medium
Confidence
81% confidence
Finding
The exception handling introduces a 'stalled' status that is not defined in the state model, creating ambiguous runtime behavior for orchestration, persistence, and resume logic. In a multi-stage pipeline with mandatory checkpoints and recovery semantics, undefined states can be mishandled by implementations, causing stages to be resumed, skipped, or overridden incorrectly.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
This section instructs the orchestrator to score the user's performance, quote their behavior, and produce evaluative judgments that go beyond coordinating a paper-production workflow. That creates an unnecessary profiling function and may pressure users into hidden assessment, especially when the record is intended for sharing and the evaluation is mandatory.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The protocol directs scanning dialogue transcripts and internal agent logs for analytics such as concession rates, overrides, health alerts, and failure-mode history. Even though some adjudication metadata is excluded, this still expands the orchestrator from workflow coordination into behavioral telemetry and internal monitoring, increasing collection and secondary use of sensitive interaction data.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
This skill permits optional transmission of user-derived citation and manuscript metadata to an external provider for cross-model verification. Even with a consent gate, the design increases confidentiality and data-governance risk because academic manuscripts, citation contexts, and reference metadata may contain unpublished research details, sensitive collaborations, or embargoed content, and environment-driven enablement can lead to accidental disclosure if consent handling is inconsistently implemented.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill explicitly allows dispatching raw dialogue turns, including private reasoning and unpublished material, to an external provider when cross-model mode is enabled. Even with a consent gate, this creates a real data-exfiltration surface because highly sensitive manuscript content and user interactions may be transmitted outside the primary trust boundary.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are broad natural-language requests such as wanting to write a research paper or review a paper, which can overlap with ordinary user intent and cause the orchestrator to activate unexpectedly. In a multi-skill environment, this can lead to misrouting, unnecessary stateful workflow initiation, or accidental invocation of downstream research/writing/review behaviors the user did not explicitly opt into.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill description does not prominently warn that Stage 6 generates and retains a record of the human-AI collaboration history, even though later sections describe process-record production and audit artifacts. In a workflow handling raw research materials and iterative user dialogue, weak upfront disclosure undermines informed consent and can lead to unexpected retention of sensitive academic or personal content.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The trigger phrase 'make slides' is broad, natural language that can easily appear in ordinary conversation and unintentionally invoke another skill. In an orchestrated agent environment, this can cause unintended cross-skill activation, surprising data flow into a presentation generator, or execution of actions the user did not mean to authorize in that moment.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The phrase 'make an interactive webpage' is similarly broad and can trigger a separate skill from ordinary user wording without sufficient activation constraints. In context, the pipeline holds substantial document content, so accidental invocation could expose draft materials to another transformation workflow or launch an unwanted publishing-oriented process.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger examples for entering external review mode are broad and loosely defined, which can cause the orchestrator to switch workflows based on ambiguous user text rather than explicit intent. In a multi-stage academic pipeline, this can misroute documents into revision/response handling, leading to incorrect processing of user inputs, accidental ingestion of unrelated files or comments, and integrity-check behavior that no longer matches the user's actual task.

Vague Triggers

Medium
Confidence
85% confidence
Finding
Using broad phrases like 'pause' or especially 'stop here' as unconditional control triggers can collide with ordinary discussion text, quoted material, or user commentary. In an agentic orchestrator, that ambiguity can be exploited to interrupt execution, alter state progression, or force unintended persistence behavior without a clearly scoped command.

Vague Triggers

Medium
Confidence
90% confidence
Finding
Accepting any 'unambiguous natural-language equivalent' as a terminal acknowledgement is too permissive for the final state transition to completed. An attacker or accidental phrasing could be interpreted as acceptance, prematurely closing the run and preventing further review or corrections while marking deliverables as finalized.

Natural-Language Policy Violations

Medium
Confidence
82% confidence
Finding
The protocol includes AI-writing indicators such as formulaic English transition phrases and stylistic heuristics without clearly limiting them by language, discipline, or user consent. In an academic pipeline that may process multilingual submissions, this can cause biased or misleading originality flags, especially for non-native English writers, and may pressure users to alter legitimate writing based on unreliable signals.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The protocol says to compile a complete collaboration history with verbatim user quotes, decision history, and shareable reporting output, but it does not require a privacy warning, redaction step, or sensitivity review. That can lead to inadvertent disclosure of confidential research topics, personal data, or sensitive instructions when the generated record is exported or shared.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrase "status" is extremely generic and likely to appear in many unrelated conversations, which can cause unintended invocation of this orchestrator skill. In an agentic workflow, accidental activation can expose workflow state, disrupt routing to more appropriate skills, or cause the system to enter a complex multi-stage pipeline when the user did not intend it.

External Transmission

Medium
Category
Data Exfiltration
Content
endpoint="${ARS_OPENAI_COMPAT_BASE_URL%/}/chat/completions"
GUARD=the cross-model verification module

resp="$(curl -sS -w '\n%{http_code}' "$endpoint" \
  -H "Authorization: Bearer $ARS_OPENAI_COMPAT_API_KEY" \
  -H "Content-Type: application/json" \
  -d "$(jq -n --arg model "$ARS_CROSS_MODEL" --arg prompt "$PROMPT" '{
Confidence
87% confidence
Finding
This section documents transmission of user-supplied citation/reference context to an arbitrary OpenAI-compatible endpoint defined by environment variables. Although the document includes consent language and dedicated-key isolation, the compatible-provider path is explicitly ungrounded and can send potentially sensitive manuscript material to third-party infrastructure, so misconfiguration or overbroad use could cause privacy or confidentiality leakage.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.