Paper Navigator
ListedPaper Navigator — provides AI agent assistance for software development workflows.
Install on your platform
Showing Claude Code. One command installs this skill into any of the agents below.
- 1
Run this in your project
terminal$ npx skills add evoscientist/evoskills --skill paper-navigator -a claude-code Uses the open-source
skillsCLI and needs Node.js. Add-gto install it for your user instead of this project.
What we know about this skill
Publisher
evoscientist
Taken from the source listing. We haven't verified who controls this account.
Install target
Live repository
Not pinned. Installing fetches whatever the repository holds at the time you run the command.
Automated safety checks
This skill failed 2 of 6 checks. A failure is not proof of bad intent; it means something in the code needs a human to look at it before you run it.
No undeclared network calls: failed
Contacts 8 hosts that are neither well-known infrastructure nor declared in the skill's frontmatter: api.openalex.org, api.semanticscholar.org, api.unpaywall.org, arxiv.org, doi.org….
Every host the skill dials — from its scripts, its config endpoints or the commands it tells the agent to run — is either well-known package and API infrastructure or declared in its own frontmatter. Links in documentation are not counted.
Hosts contacted
github.comsource hostarxiv.orgundeclaredhuggingface.comodel providerapi.unpaywall.orgundeclareddoi.orgundeclaredapi.semanticscholar.orgundeclaredapi.github.comsource hostr.jina.aiundeclaredmarkxiv.comundeclaredapi.cohere.commodel provideropenrouter.aimodel providerexport.arxiv.orgundeclaredapi.openalex.orgundeclaredWhat it found (3 of 21)
- skills/paper-navigator/scripts/arxiv_monitor.py:37contacts arxiv.org
f"https://arxiv.org/pdf/{arxiv_id}" if arxiv_id else "" - skills/paper-navigator/scripts/download_paper.py:62contacts arxiv.org
return f"https://arxiv.org/pdf/{arxiv_id}.pdf", arxiv_id - skills/paper-navigator/scripts/fetch_paper.py:103contacts arxiv.org
url = f"https://arxiv.org/abs/{arxiv_id}"
No credential access: failed
Touches credential material in 3 places.
Neither the code nor the SKILL.md instructions read SSH keys, cloud credentials, keychains, token stores, browser cookie databases or dotfiles that hold secrets.
What it found
- skills/paper-navigator/scripts/deepxiv_client.py:9environment file outside the project
the environment first, then from ``./.env`` and ``~/.env`` — the same files the - skills/paper-navigator/scripts/deepxiv_client.py:64environment file outside the project
the same keys in ``./.env`` and ``~/.env`` (written by ``deepxiv config`` / - skills/paper-navigator/SKILL.md:38instructs the agent to access environment file outside the project(in the instructions, not code)
| `DEEPXIV_API_TOKEN` | `arxiv_monitor`, `scholar_search` fallback | Get a free token: `deepxiv token` (writes `~/.env`). Also read from `DEEPXIV_TOKEN` and `.…
Declares what it does: passed
SKILL.md parses and declares a name and a description.
SKILL.md exists, its frontmatter parses, and it declares a name and a description.
No obfuscated payloads: passed
No encoded or obfuscated payloads.
No base64, hex or compressed blob is decoded and then executed, and no encoded shell commands.
No pipe-to-shell installers: passed
No pipe-to-shell or download-and-run installers.
No `curl … | sh` pattern, in the code or in the instructions, that runs code fetched at run time.
Pinned to a commit: passed
Scanned evoscientist/evoskills at 7dde27cda0.
The exact upstream commit SHA that was scanned is recorded, so the result refers to specific bytes.
- Commit
- 7dde27cda0
- Manifest
- skills/paper-navigator/SKILL.md
- Scanned
- 30 files, 7,061 lines
About this skill
Paper Navigator — provides AI agent assistance for software development workflows.