Back to skill

Security audit

Research Pipeline

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only research automation skill that is coherent, but it can write Obsidian notes and send Feishu digests when used with those integrations.

Install this only if you want automated literature research that can create Obsidian notes and send Feishu messages. Before enabling cron or unattended runs, confirm the Obsidian vault/folder, Feishu recipient, and permissions of the delegated arXiv, summarizer, Obsidian, and Feishu tools.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The manifest description includes broad activation phrases such as 'research a topic', 'find papers', 'do a literature review', and automatic daily triggering. This can cause the skill to activate in situations broader than the user expects, leading to unsolicited searches, note creation, and outbound messaging through connected tools.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs the agent to create literature notes in Obsidian but does not warn that this modifies user files and may persist inaccurate, sensitive, or unwanted content. In this context, the risk is elevated because the workflow is automated and may run from cron, so side effects can occur without an interactive checkpoint.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill sends research digests via Feishu without disclosing this outbound communication in a user-facing warning. That creates a risk of unintended data exfiltration, spam, or disclosure of research interests and generated summaries to external messaging channels, especially when triggered automatically by cron.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.