Back to skill

Security audit

Quantum Distribution Generator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for calling a disclosed AgentPMT statistical sampling tool; the main caution is that it sends requests to a paid remote service.

Install this if you intend your agent to call AgentPMT for statistical distribution sampling and you are comfortable with remote requests and credit usage. Review any separate AgentPMT setup skill before connecting credentials, tokens, wallets, or payment methods.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The schema exposes a `randomwalk` action that is not described in the manifest/declared skill surface, creating a documentation-to-capability mismatch. Hidden or undocumented actions are dangerous because agents, reviewers, and policy layers may validate against the manifest while the backend still permits additional behavior, increasing the risk of unauthorized tool use, bypass of governance checks, and unexpected cost or resource consumption.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill advertises activation keywords including very broad terms like "beta," "source," and "count," which are common across many unrelated tasks. This can cause accidental invocation of the remote tool in contexts where the user did not intend external calls, increasing the risk of unnecessary data transmission, unintended charges, or workflow hijacking through overmatching.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.