arxiv-source-first-paper-ingest
Fail
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: Suspicious dependency injection in Cargo.lock files. The lock files for both 'tools/arxiv-latex-display-math-extractor' and 'tools/latex-math-validity-oracle' include tampered dependency lists for the well-known library 'serde_json'. Specifically, these files list unknown packages 'zmij' and 'serde_core' as dependencies, which is a signature pattern for supply chain attacks using dependency confusion or registry poisoning.\n- [DYNAMIC_EXECUTION]: Execution of untrusted LaTeX code via system tools. The script 'tools/compile_each_formula_with_real_tex_engine.ts' uses Bun's shell command execution to run 'pdflatex' on mathematical formulas extracted from external arXiv e-prints. Since arXiv allows user uploads, this content is untrusted and LaTeX engines can be exploited for arbitrary command execution if the environment is not sufficiently restricted.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from arXiv.org, a public repository of user-submitted academic papers. Maliciously crafted LaTeX source code could be used to inject hidden instructions or deceptive data into the agent's context when it processes the 'faithfully' extracted equations and theorems.\n- [COMMAND_EXECUTION]: The skill's operational flow involves fetching remote archive files from the internet and extracting them ('curl | tar'), followed by the compilation and execution of local Rust binaries and TypeScript scripts that interact directly with the host shell and file system.
Recommendations
- AI detected serious security threats
Audit Metadata