Back to skill

Security audit

Academic Deep Research Pro

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed research workflow skill that uses web research tools after user approval, with no evidence of hidden installation, credential access, persistence, or destructive behavior.

Install only if you want an agent to run multi-step web research on your approved topics. Treat research subjects as potentially exposed through external search/fetch activity, and be aware that the workflow may make many web requests once you approve the plan.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The README advertises broad natural-language triggers such as asking for "deep research on..." or "exhaustive analysis of...", which can cause the skill to activate during ordinary conversation rather than only through an explicit command. In an agent environment, overly generic invocation phrasing increases the chance of accidental routing into a high-autonomy research workflow that performs web searches/fetches and consumes resources without clear user intent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The invocation phrase includes generic language like "deep research" and "exhaustive analysis," which can be used in ordinary conversation and may unintentionally trigger the skill. Because this skill performs automated multi-step web research, accidental invocation can cause unexpected external access, resource consumption, and user confusion about when autonomous browsing begins.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The quick reference describes an automated execution phase using web_search and web_fetch, but it does not prominently warn that the skill will perform external web access autonomously after plan approval. This can undermine informed consent and may expose sensitive prompts, research topics, or organizational intent through outbound queries to third-party services.

Autonomous Decision Making

Medium
Category
Excessive Agency
Content
---

## Phase 3: Research Cycles (Auto-Execute)

### Theme 1: Market Landscape — Cycle 1
Confidence
76% confidence
Finding
Auto-Execute

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.