Back to skill

Security audit

arXiv Decision Intelligence

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed arXiv research-report workflow with local helper scripts and no evidence of hidden persistence, credential use, or destructive behavior.

Install this if you want an arXiv-centered field-intelligence report workflow and are comfortable with it searching arXiv/academic sources and saving raw, normalized, JSON, and HTML report artifacts locally. Be aware that the report language is effectively fixed to Simplified Chinese with preserved English titles, and the workflow depends on the separate literature-search-arxiv skill plus uv.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (17)

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description promises a high-level research and analysis skill that searches arXiv, optionally verifies external sources, synthesizes findings into decision-oriented analytical frameworks, and outputs a restrained bilingual standalone HTML report. The supplied code does none of that. It is only a post-processing/normalization script for already-produced arXiv JSON output. While this could be a supporting component within a larger pipeline related to arXiv research, on its own its primary purpose is materially narrower and different from the declared end-user capability. There are no concerning extra permissions or resource accesses, but the behavior shown is substantially underinclusive relative to the description, so this is a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

This is a clear description-behavior mismatch. The declared purpose centers on conducting academic search/verification and producing a field-intelligence report. The actual code chunk instead validates the structure and internal consistency of a preexisting JSON report file. While the validator's schema aligns with the described report format and analytical concepts, it is only a supporting quality-control component, not the main described skill behavior. There are also no declared permissions, and the code correspondingly performs no external access; however, the key mismatch is that the implemented capability is validation rather than search, verification, synthesis, or HTML generation.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The description presents a research-and-reporting skill whose primary function is to search literature, verify sources, analyze evidence, and produce a bilingual HTML report. The actual code chunk does none of that. Instead, it is a static/offline QA tool that checks whether a supplied HTML artifact and associated data conform to a required schema and presentation contract. This is a materially different primary purpose, not just a supporting implementation detail. No undeclared dangerous capability is present, but the declared functionality is significantly overstated relative to the supplied code.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 57)May include surrounding context.

md
complete `SKILL.md` first and obey its license notification, rate limit,

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 494)May include surrounding context.

md
- `assets/report.css` and `examples/sample-report.json` — visual system and v3 example.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill instructs the agent to read local files, write outputs, and access network resources, but it does not declare an explicit tool/permission scope. That creates an authorization ambiguity: a host may permit broader file or network operations than the user expects, increasing the chance of unintended data access, exfiltration, or writes during execution.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown explicitly states that Chinese is the primary editorial language and instructs outputs accordingly. This is a language/locale constraint presented as a default behavior without offering the user a choice or opt-in, which matches the policy-violation category for locale/language restrictions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The defaults specify Language/output: zh-CN unless otherwise requested, which establishes a forced locale as the standard behavior. Because the file does not present an explicit user choice flow and instead prescribes a locale by default, this is a natural-language policy concern under the language/locale rule.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The rubric explicitly instructs the agent to use Chinese for reasoning, which can override or conflict with the user's language preference and reduce transparency for users, reviewers, or downstream systems expecting English. In a research-analysis skill, this is especially risky because it can hide substantive reasoning from the user, impair informed review, and create consent/usability issues rather than a direct code-execution exploit.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The schema hard-codes the report language to "zh-CN" via a const value, which enforces a specific locale for all conforming outputs. Under the policy, forcing a language or locale without offering user choice or documenting a justified region-specific constraint is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

This code emits the final document with <html lang="zh-CN">, which forces a specific locale for all rendered reports regardless of user preference or input context. The file does not offer a language choice or document a region-specific compliance reason for requiring Simplified Chinese, so it conflicts with the language/locale policy criteria.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This code rejects any report whose language is not exactly 'zh-CN', creating a hard locale requirement. Under the policy, forcing a specific language without user choice or an explicitly documented region-specific justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The verifier rejects any HTML document whose root language is not exactly zh-CN, which imposes a fixed language/locale requirement. Under the policy, forcing a specific language without user opt-in or a clearly documented justification is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The phrase 'deterministic standalone HTML report with restrained Chinese/English typography' imposes a specific language/locale presentation in the skill description. The policy allows locale constraints only when user choice or clear justification is provided, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
81% confidence
Finding

The font stacks explicitly prioritize Simplified Chinese serif and sans-serif families such as "Noto Serif SC", "Source Han Serif SC", "Songti SC", "Noto Sans SC", and "PingFang SC". In an all-file-types policy review, this can be a natural-language locale preference baked into the asset without any visible indication of user opt-in or a documented region-specific justification in the file.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

This file declares the document language as "zh-CN" at L0002 and the visible content is primarily Chinese, but there is no natural-language indication that this locale is optional or scoped to a China-specific audience. The policy requires flagging language or locale constraints that are imposed without user opt-in or clear justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
97% confidence
Finding

This manifest-style JSON explicitly sets the report language to "zh-CN". Because the file does not indicate that language selection is optional, user-configurable, or justified as a region-specific constraint, it appears to impose a locale choice unilaterally.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.