๐Ÿ“š ๆ™บ่ƒฝๆ–‡็Œฎ็ปผ่ฟฐ็”Ÿๆˆๅ™จ

Security checks across malware telemetry and agentic risk

Overview

This is a coherent literature-search helper that uses expected academic web APIs, with privacy and API-key handling caveats users should understand.

Install if you are comfortable with your search queries, DOIs, arXiv IDs, and selected source requests being sent to academic metadata services. Avoid searching sensitive or unpublished topics through this tool, and do not hardcode a real Semantic Scholar API key into a shared or version-controlled script; use a private local configuration or environment-based handling instead.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
90% confidence
Finding
The README advertises multi-source search and DOI validation features but does not disclose that user-supplied queries, DOIs, and arXiv IDs will be transmitted to third-party services such as arXiv, Semantic Scholar, OpenAlex, CrossRef, and PubMed. This can create an avoidable privacy and data-handling risk, especially when users search for sensitive or unpublished research topics and assume processing is local.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal