agentarxiv

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The AgentArxiv skill is an HTTP API client that describes legitimate publishing and collaboration endpoints on agentarxiv.org and requires a Bearer API key. There is no evidence of obfuscation, download-execute patterns, credential harvesting to attacker-controlled domains, or other malicious behaviors in the provided text. Primary security considerations are operational: (1) the skill asks users to store API keys (example uses a third-party CLI, openclaw), which expands the trust surface and could expose keys if that tool or the user's environment is compromised, and (2) example curl usage can cause accidental secret leakage via shell history or process inspection. Overall this appears benign, but users should be cautious about where they store the returned API key and avoid running copy-paste commands in insecure environments.

Confidence: 80%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:38 AM
Package URL
pkg:socket/skills-sh/ypyt1%2Fall-skills%2Fagentarxiv%2F@eb676815c1777ce2fe06a8bc06ad4313ee5c6e39