Back to skill

Security audit

百度学术助手 (Baidu Scholar Helper)

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a real academic paper search tool, but it downloads files and contacts broader network destinations than its formal security metadata clearly covers.

Install only if you are comfortable with a skill that searches academic sites, automatically downloads remote files to your Desktop papers folder, and may contact Semantic Scholar or PDF hosts not fully listed in the manifest. Review any sudo install command before running it, and avoid opening downloaded PDFs from untrusted sources without validation.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/enhanced_search.py:26
Finding

Plaintext arXiv metadata retrieval allows response tampering

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
scripts/main.py:61
Finding

Scraped download URLs are requested without destination validation

Content
View full analysis
5000: return filename headers = get_headers() resp = requests.get( url, headers=headers, timeout=30, allow_redirects=True ) if resp.status_code == 200 and len(resp.content) > 5000: with open(path, "wb") as f: f.write(resp.content) return filename except Exception: pass return None ``` ### Technical Analysis The code accepts absolute HTTP or HTTPS URLs obtained from Baidu Scholar search-result HTML. It does not restrict the scheme, hostname, port, resolved IP address, or redirect chain. A malicious or compromised result can therefore cause the runtime to send requests to arbitrary destinations. Even if an initial URL belongs to an expected host, `allow_redirects=True` permits the request to leave that host without further validation. In an environment with access to internal ...[truncated 1202 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/arxiv_search_v2.py:100
Finding

Automatic downloads lack maximum-size and PDF-content validation

Content
View full analysis
10000: return filename with open(path, "wb") as f: for chunk in resp.iter_content(chunk_size=8192): if chunk: f.write(chunk) file_size = os.path.getsize(path) if file_size > 10000: return filename else: os.remove(path) ``` The Baidu implementation buffers the complete response in memory and applies only a minimum-size check: ```python resp = requests.get( url, headers=headers, timeout=30, allow_redirects=True ) if resp.status_code == 200 and len(resp.content) > 5000: with open(path, "wb") as f: f.write(resp.content) return filename ``` No implementation verifies the `Content-Type` header or `%PDF-` file signature. ### Technical Analysis A timeout restricts periods of network inactivity but does not restrict the total number of bytes transferred. A server can continuously send data and consume available disk space. In `scripts/main.py`, accessing `resp.content` first buffers the entire body in memory, creating an additional memory-exhaustion risk. The checks only require files to exceed a minimum size. Consequently, HTML, executable data, parser test cases, or other arb ...[truncated 1288 chars]
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
skill.json:48
Finding

Formal network declarations omit actual third-party destinations

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
requirements.txt:2
Finding

Python dependencies use open-ended version ranges without integrity hashes

Content
View full analysis
=2.28.0 beautifulsoup4>=4.11.0 Pillow>=9.0.0 ``` The installation documentation is less restrictive: ```bash pip install requests beautifulsoup4 Pillow ``` ### Technical Analysis The listed dependencies are established packages from the standard Python ecosystem; no typosquatted name, suspicious package index, or known malicious dependency was identified in the audited files. However, the open-ended lower bounds permit any future version to be installed without review. No lock file or package hashes are supplied, so two installations performed at different times can resolve different code. This weakens build reproducibility and dependency integrity. ### Attack Path 1. A user installs the Skill at a later date. 2. The package resolver selects the newest versions satisfying the lower bounds. 3. A future compromised, unexpectedly incompatible, or behavior-changing release is installed. 4. That dependency executes in the same Python environment and with the same network and file permissions as the Skill. ### Impact Assessment The potential impact is bounded by the privileges of the installation and runtime environment. A compromised dependency could access files and networks available to the Skill. The current repository does not demonstrate that any listed package is malicious, so this is a preventive supply-chain finding rather than evidence of an active malicious package. ]]>
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (40)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
85% confidence
Finding

All user-facing instructions and examples in the README are written in Chinese, and there is no indication that other languages are supported or that the skill is intentionally limited to Chinese-speaking users. Under the stated policy, forcing a specific language without user opt-in is a natural-language policy concern.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The listed triggers, activation condition, and dialogue examples are written exclusively in Chinese and imply the skill is invoked and operated in that language only. There is no indication that users may choose another language or that the Chinese-only behavior is a justified regional constraint.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger 搜论文 and the when condition "用户需要检索论文、下载PDF、总结工作创新点、按引用量排序时" are broad natural-language activators without clear scope boundaries. They do not include exclusion conditions or negative examples, so the skill could be invoked for many ordinary research-related requests unintentionally.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 129)May include surrounding context.

md
# 系统依赖安装(根据操作系统选择)
  system:
    ubuntu:
      - sudo apt-get install -y poppler-utils
    debian:
      - sudo apt-get install -y poppler-utils
    macos:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 131)May include surrounding context.

md
# 系统依赖安装(根据操作系统选择)
  system:
    ubuntu:
      - sudo apt-get install -y poppler-utils
    debian:
      - sudo apt-get install -y poppler-utils
    macos:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
# 系统依赖安装(根据操作系统选择)
  system:
    ubuntu:
      - sudo apt-get install -y poppler-utils
    debian:
      - sudo apt-get install -y poppler-utils
    macos:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 137)May include surrounding context.

md
# 系统依赖安装(根据操作系统选择)
  system:
    ubuntu:
      - sudo apt-get install -y poppler-utils
    debian:
      - sudo apt-get install -y poppler-utils
    macos:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 179)May include surrounding context.

Ubuntu/Debian:

bash
sudo apt-get install -y poppler-utils

macOS:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 189)May include surrounding context.

Ubuntu/Debian:

bash
sudo apt-get install -y poppler-utils

macOS:

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 191)May include surrounding context.

Ubuntu/Debian:

bash
sudo apt-get install -y poppler-utils

macOS:

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script creates a fixed directory on the user's Desktop and later writes downloaded PDFs there automatically, without prompting the user or requiring explicit opt-in for filesystem changes. While this is not arbitrary file write, it is still a real safety issue because executing the skill causes persistent local side effects and network-fetched content to be saved to a prominent user location by default.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically downloads remote PDFs and writes them to a fixed Desktop directory without any user confirmation, dry-run mode, or opt-in flag. In an agent/skill context, this can cause unintended filesystem modification, silent disk usage, and retrieval of untrusted content from the network, which is risky even if the files are 'just PDFs'.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script creates a Desktop subdirectory up front and later, by default, downloads PDFs into it without explicit user confirmation. While this appears intended functionality for a paper-search tool rather than malicious behavior, it still performs local writes and network-driven file downloads automatically, which can surprise users, consume disk space, and persist untrusted content on the host.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/enhanced_search.py (reported line 27)May include surrounding context.

python
# API端点
ARXIV_API = "http://export.arxiv.org/api/query"
SEMANTIC_SCHOLAR_API = "https://api.semanticscholar.org/graph/v1/paper/search"

def clean_filename(title):
    """清理文件名"""

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

This Python file contains user-facing natural language entirely in Chinese, including the tool name, feature description, and later CLI messages, with no indication that the user can choose another language. Under the policy, forcing a specific language without user opt-in is a natural-language policy violation unless the locale restriction is documented and justified.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/extract_model_figure.py (reported line 26)May include surrounding context.

python
"""提取页面文字用于分析图片标题"""
    try:
        cmd = ["pdftotext", "-f", str(page_num), "-l", str(page_num), "-layout", pdf_path, "-"]
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)
        return result.stdout.lower()
    except:
        return ""

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/extract_model_figure.py (reported line 183)May include surrounding context.

python
# 使用pdfimages提取图片
        cmd = ["pdfimages", "-png", "-f", str(page_num), "-l", str(page_num), 
               pdf_path, os.path.join(output_dir, f"{prefix}_p{page_num}")]
        subprocess.run(cmd, capture_output=True, timeout=30)
        
        # 找到生成的图片
        for f in os.listdir(output_dir):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script creates a Desktop folder automatically and later downloads remote PDF content into it without any explicit user confirmation, dry-run mode, or opt-in for filesystem writes. In an agent/skill context, this is risky because a user may trigger a search expecting read-only behavior, while the skill silently persists untrusted internet content to a highly visible local path and can clutter storage or introduce unsafe files disguised as PDFs.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The docstring and all user-facing usage/help text are entirely in Chinese, which imposes a language requirement on users without any opt-in or alternative locale. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale restriction is explicitly justified.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script automatically downloads PDFs for every search result and writes them to the user's Desktop without any confirmation, opt-in, or dry-run mode. This can cause unexpected network activity, disk consumption, and unreviewed file placement from remote content, which is risky in an agent skill context where users may expect search-only behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill name and description are entirely in Chinese, with no indication that users can opt into another language or that the skill is intentionally limited to a Chinese-language audience. This can violate language/locale policy when a skill implicitly forces one language without user choice or justification.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This is a manifest file, so vague-trigger review applies. The description is purely capability-focused and broad ('一键搜索学术论文,自动下载PDF,智能总结...') without any explicit activation phrases, boundaries, or negative examples, which can make invocation conditions unclear in systems that derive triggers from manifest text.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The install manifest instructs use of 'sudo apt-get install -y poppler-utils', which normalizes privileged execution during setup. While installing a package manager dependency is common, embedding sudo-based commands in a skill can lead users to run elevated commands they do not fully audit, increasing the blast radius if the manifest or surrounding install flow is ever tampered with.

Content

Scanner excerpt · skill.json (reported line 29)May include surrounding context.

json
"Pillow>=9.0.0"
    ],
    "system": {
      "ubuntu": "sudo apt-get install -y poppler-utils",
      "debian": "sudo apt-get install -y poppler-utils",
      "macos": "brew install poppler",
      "fedora": "sudo dnf install -y poppler-utils",

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The manifest includes 'sudo apt-get install -y poppler-utils' for Debian, encouraging privileged execution as part of installation. Even though the package itself appears legitimate, prompting users to run root-level commands from skill metadata creates avoidable trust and supply-chain risk.

Content

Scanner excerpt · skill.json (reported line 30)May include surrounding context.

json
],
    "system": {
      "ubuntu": "sudo apt-get install -y poppler-utils",
      "debian": "sudo apt-get install -y poppler-utils",
      "macos": "brew install poppler",
      "fedora": "sudo dnf install -y poppler-utils",
      "centos": "sudo yum install -y poppler-utils"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
93% confidence
Finding

The Fedora install command uses 'sudo dnf install -y poppler-utils', again requiring elevated privileges based on manifest content. In the context of a skill that already requests network, file-write, and subprocess permissions, encouraging root-level setup increases risk if users broadly trust the package without scrutiny.

Content

Scanner excerpt · skill.json (reported line 32)May include surrounding context.

json
"ubuntu": "sudo apt-get install -y poppler-utils",
      "debian": "sudo apt-get install -y poppler-utils",
      "macos": "brew install poppler",
      "fedora": "sudo dnf install -y poppler-utils",
      "centos": "sudo yum install -y poppler-utils"
    }
  },

Static analysis

No suspicious patterns detected.