Back to skill

Security audit

arXiv Paper Reviews

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent arXiv paper API client, but it sends API keys and user-submitted review content to a remote service over unencrypted HTTP.

Review carefully before installing. Use this only for non-sensitive paper searches and comments unless the API base URL is changed to HTTPS and API keys are protected. Do not put a valuable API key or private review content into this skill while it uses the default HTTP endpoint; rotate any key already used through that endpoint.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Error
Location
config.json:2
Finding

API Credentials and User Content Transmitted over Plaintext HTTP

Content
View full analysis

Vulnerability Details

File Location: config.json:2, SKILL.md:4,38,43, paper_client.py:31-36,52-59,91-97,135-153
Vulnerability Type: Sensitive information transmitted over an unencrypted network connection
Risk Level: High

Vulnerable Code

config.json:1-5:

json
{
  "apiBaseUrl": "http://weakaccept.top:8000/",
  "apiKey": "",
  "defaultAuthorName": ""
}

paper_client.py:31-36:

python
def get_headers(config):
    """Get request headers (including API Key if configured)"""
    headers = {}
    if config.get("apiKey"):
        headers["X-API-Key"] = config["apiKey"]
    return headers

paper_client.py:52-59:

python
def cmd_list(args):
    """Fetch paper list"""
    config = load_config()
    url = f"{get_api_base(config)}/v1/papers"

    params = {"limit": args.limit}
python
    headers = get_headers(config)

    response = requests.get(url, params=params, headers=headers)

paper_client.py:135-153:

python
def cmd_comment(args):
    """Add comment"""
    config = load_config()
    url = f"{get_api_base(config)}/public/papers/{args.paper_key}/comments"

    # If author name not specified, use default from config
    author_name = args.author_name or config.get("defaultAuthorName", "Anonymous")

    data = {
        "content": args.content,
        "author_name": author_name
    }

    response = requests.post(
        url,
        headers={"Content-Type": "application/json"},
        json=data
    )

Technical Analysis

The default API URL uses plaintext HTTP rather than HTTPS. The client derives every endpoint from this value without validating the scheme or requiring transport encryption.

When an API key is configured, get_headers() places it in the X-API-Key request header for the authenticated list and paper-detail operations. Review submissions separately transmit user-provide ...[truncated 2161 chars]

Remediation
View remediation

Remediation Suggestions

  1. Replace the default endpoint with an HTTPS URL backed by a valid certificate:
    json
    {
      "apiBaseUrl": "https://weakaccept.top/",
      "apiKey": "",
      "defaultAuthorName": ""
    }
    
  2. Validate apiBaseUrl before making any request and reject schemes other than https.
  3. At minimum, unconditionally reject HTTP whenever an API key, author identity, comment, or other potentially sensitive value would be transmitted.
  4. Keep normal TLS certificate and hostname verification enabled. Do not introduce verify=False.
  5. Consider restricting the permitted host to the expected API hostname to reduce accidental credential transmission to an attacker-controlled endpoint.
  6. Store API keys outside the project file where possible, such as in a protected environment variable or operating-system credential store.
  7. Rotate any API key that has already been used through the plaintext endpoint.
  8. Add connection and read timeouts and handle requests exceptions so a malicious or unavailable endpoint cannot hang the client indefinitely.

T08 · Insecure Dependencies

Warning
Location
install-deps.sh:7
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: install-deps.sh:7-14, SKILL.md:27-35
Vulnerability Type: Mutable and non-reproducible dependency resolution
Risk Level: Medium

Vulnerable Code

install-deps.sh:7-14:

bash
# Check if venv exists, if not create it
if [ ! -d "venv" ]; then
    echo "Creating virtual environment..."
    python3 -m venv venv
fi

# Activate venv and install requests
source venv/bin/activate
pip install -q requests

SKILL.md:27-35:

bash
pip3 install requests
# Or use a virtual environment
python3 -m venv venv
source venv/bin/activate
pip install requests

Technical Analysis

Both documented installation paths and the installation script request requests without specifying a reviewed version, constraining transitive dependencies, or verifying package hashes. Consequently, the installed dependency graph depends on the package-index state at installation time.

This makes installations non-reproducible and allows a future release or changed transitive dependency to enter the execution environment without a corresponding review of this Skill. A compromised package-index account, compromised upstream release, or subsequently unsafe package version could therefore affect new installations.

The script does create a virtual environment, which limits installation to that environment under normal use. It does not install system-wide packages or request elevated privileges. Nevertheless, code imported from that environment executes with the privileges of the user running paper_client.py.

Attack Path

  1. A user runs bash install-deps.sh or follows the installation commands in SKILL.md.
  2. pip resolves the current version of requests and its transitive dependencies from the configured package index.
  3. If an upstream account, release, dependency, or configured index has been compromised, pip retrieves the affected distribution.
  4. P ...[truncated 933 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin requests and all transitive dependencies to versions that have been reviewed and tested.
  2. Generate and commit a lock file or hashed requirements file. Install with hash enforcement, for example:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Use python3 -m pip rather than an unqualified pip command to ensure installation targets the intended interpreter.
  4. Configure an explicitly trusted package index and avoid unexpected user-level index overrides where the deployment model permits it.
  5. Regularly scan pinned dependencies for known vulnerabilities and update them through a controlled review process.
  6. Keep installation inside the virtual environment and do not recommend running the installation script with sudo or as root.
  7. Update SKILL.md so every documented installation method uses the same locked, hash-verified dependency set.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
95% confidence
Finding

The skill invokes network access and reads local configuration, but it does not declare any tool scope or permission boundaries. That makes the skill's effective capabilities less transparent to users and host systems, increasing the risk of unintended data access or outbound requests to an untrusted service.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill directs users to send API requests and review content to a third-party service over plain HTTP, which provides no transport encryption or strong server authentication. Comments, API keys, paper queries, and other metadata could be intercepted or modified in transit, and the description fails to warn users that their content is being transmitted externally and insecurely.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · paper_client.py (reported line 159)May include surrounding context.

python
"author_name": author_name
    }

    response = requests.post(
        url,
        headers={"Content-Type": "application/json"},
        json=data

Static analysis

No suspicious patterns detected.