deepxiv

Warn

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill employs dynamic logic to resolve the location of its execution scripts (deepxiv_fetch.py and research_wiki.py). It calculates these paths at runtime by reading configuration files (e.g., .aris/installed-skills.txt, $HOME/.aris/repo) and checking environment variables (ARIS_REPO). The resolved paths are subsequently used in python3 command executions.
  • [EXTERNAL_DOWNLOADS]: The skill explicitly directs the user to install the deepxiv-sdk package from an external registry using pip to enable its core functionality.
  • [COMMAND_EXECUTION]: The skill uses shell commands to perform its operations. User-supplied input from $ARGUMENTS is interpolated into shell command templates (e.g., python3 "$DEEPXIV_FETCHER" search "QUERY"), which could lead to command injection if the underlying agent platform does not strictly sanitize the input string.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external academic papers, which are not under the skill's control.
  • Ingestion points: The skill fetches paper briefs, metadata summaries, and specific section text via the DeepXiv CLI or adapter script.
  • Boundary markers: There are no instructions or delimiters defined to prevent the agent from following potentially malicious instructions embedded within the retrieved academic text.
  • Capability inventory: The skill possesses Bash, Read, and Write capabilities, allowing it to perform actions in the local environment based on the content it processes.
  • Sanitization: The workflow does not include any validation or filtering steps for the content retrieved from external sources before it is presented to the agent or written to the research wiki.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 29, 2026, 02:42 PM
Security Audit — agent-trust-hub — deepxiv