deepxiv
Warn
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The skill employs dynamic logic to resolve the location of its execution scripts (
deepxiv_fetch.pyandresearch_wiki.py). It calculates these paths at runtime by reading configuration files (e.g.,.aris/installed-skills.txt,$HOME/.aris/repo) and checking environment variables (ARIS_REPO). The resolved paths are subsequently used inpython3command executions. - [EXTERNAL_DOWNLOADS]: The skill explicitly directs the user to install the
deepxiv-sdkpackage from an external registry usingpipto enable its core functionality. - [COMMAND_EXECUTION]: The skill uses shell commands to perform its operations. User-supplied input from
$ARGUMENTSis interpolated into shell command templates (e.g.,python3 "$DEEPXIV_FETCHER" search "QUERY"), which could lead to command injection if the underlying agent platform does not strictly sanitize the input string. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external academic papers, which are not under the skill's control.
- Ingestion points: The skill fetches paper briefs, metadata summaries, and specific section text via the DeepXiv CLI or adapter script.
- Boundary markers: There are no instructions or delimiters defined to prevent the agent from following potentially malicious instructions embedded within the retrieved academic text.
- Capability inventory: The skill possesses
Bash,Read, andWritecapabilities, allowing it to perform actions in the local environment based on the content it processes. - Sanitization: The workflow does not include any validation or filtering steps for the content retrieved from external sources before it is presented to the agent or written to the research wiki.
Audit Metadata