Back to skill

Security audit

arXiv Decision Intelligence

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent arXiv research-reporting workflow that discloses its network research, local file outputs, and Chinese-first report defaults.

Installers should expect the skill to run arXiv searches, retrieve papers through a separate arXiv skill, save raw public research responses, and create local JSON/HTML reports. Request English or another language up front if the Chinese-first default is not suitable.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
The skill mandates Chinese as the primary editorial language without user opt-in, which can override user expectations and cause outputs to be generated in an unintended language. In security-sensitive or decision-support contexts, forced localization can impair review, hide meaning from the operator, and increase the risk of misunderstanding or missed issues, especially when the user expected English output.

Natural-Language Policy Violations

Medium
Confidence
95% confidence
Finding
Fixing the default output locale to `zh-CN` without explicit opt-in creates the same control and comprehension risk at the workflow default level. Because this skill produces high-stakes research and decision artifacts, an unexpected language default can materially affect usability, verification, and downstream decision quality.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.