AMiner Academic Search

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward AMiner academic-search skill that discloses its API-token use and paid endpoints, with no packaged executable code or hidden behavior found.

Install only if you are comfortable sending academic queries, names, identifiers, and token-authenticated requests to AMiner. Keep the token in a secret or environment variable, review paid endpoint costs before repeated or bulk searches, and inspect any external aminer_client.py script before running it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger list includes broad English and Chinese phrases such as "academic search," "paper search," and "scholar lookup," which can match ordinary user requests and cause the skill to activate unexpectedly. Because this skill sends user queries and a bearer token to a third-party academic data service, overbroad triggering increases the chance of unintended external data disclosure and unwanted paid API usage.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill does not clearly warn users that their search queries and token-authenticated requests are transmitted to AMiner, a third-party service. In this context, queries may contain sensitive research topics, institutional interests, or personal names, so lack of disclosure undermines informed consent and can lead to privacy leakage and unexpected external processing.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal