Back to skill

Security audit

Db Table Compare

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a database/schema helper whose sensitive access is expected for its purpose, but users should invoke it only for authorized, explicit targets.

Before installing or using it, confirm it will only run against databases and SSH hosts you control or are authorized to inspect. Give explicit source/target environment names and table scope, prefer read-only credentials for schema checks, and require review before applying any generated ALTER statements.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger phrases are very broad and generic, such as requests to compare table fields or generate alter statements, without requiring explicit confirmation of target systems, environments, or authorization context. In a skill that can drive SSH and database schema inspection across multiple production-like data sources, this increases the chance of unintended invocation and accidental exposure of internal schema metadata.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.