Back to skill

Security audit

JARVIS AI Skills

Security checks across malware telemetry and agentic risk

Overview

This skill clearly aims to control real robotic arms and grippers, but it lacks safety limits or confirmation guidance for potentially dangerous physical movement.

Review carefully before installing. Treat it as simulation-only unless you independently audit the missing control module and ensure emergency stop, access control, workspace limits, speed and force caps, and explicit operator confirmation for every motion or gripper command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

High
Confidence
98% confidence
Finding
This skill exposes voice and programmatic control for a physical robotic arm and gripper, including movement, grabbing, releasing, and homing, but provides no visible user warnings, operating constraints, or hazard disclosures. In a safety-critical robotics context, omission of clear warnings can lead to unsafe use around people, property damage, pinching/crushing injuries, or unintended activation of high-payload equipment.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This manifest exposes direct robotic arm and gripper operations such as movement, rotation, grabbing, and release, but provides no warnings, safety constraints, or operator guidance about physical-world hazards. In a hardware-control skill, omission of safety messaging and guardrails increases the chance of unintended motion, pinching, collision, or damage to nearby people and objects if the skill is invoked incorrectly or integrated unsafely.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.