Back to skill

Security audit

AGENTIC AI GOLD STANDARD

Security checks across malware telemetry and agentic risk

Overview

This skill does not show malware, but its advertised always-on self-improving agent and security controls are not backed by the included implementation or clear operating boundaries.

Review carefully before installing. Treat the self-improvement, 17 security gates, 24/7 council, integration-test, and production-connectivity claims as unverified unless the publisher provides real implementation and tests. If you experiment, use an isolated environment, pin dependencies, avoid sensitive data, use least-privilege API keys, and do not grant unattended write or production tool access without explicit approvals, logs, and rollback controls.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
90% confidence
Finding
The skill metadata markets a sophisticated self-improving and security-hardened framework, while the analyzed content provides no supporting implementation and the static finding indicates unrelated side effects such as package installation and filesystem changes. This mismatch is dangerous because users may grant elevated trust, permissions, or execution based on false security claims, increasing the chance of unsafe deployment and supply-chain exposure.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The example claims agents terminate after task completion, but every created specialist is retained indefinitely in the class-level `_registry`. In a real agent framework, this discrepancy can lead to resource retention, stale agent references, privacy exposure through lingering task data, and operator trust issues because lifecycle guarantees are false.

Intent-Code Divergence

Low
Confidence
87% confidence
Finding
The code asserts that it is running '17 dharmic security checks' but only performs five hardcoded checks, creating a misleading security claim. In security-sensitive agent infrastructure, overstated controls can cause users to trust protections that do not actually exist, weakening governance and review rigor.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The module docstring presents the example as enabling real overnight self-improvement, but the implementation only prints messages and generates random values. In an agent framework, this kind of deceptive capability claim can mislead operators into trusting nonexistent safeguards, automation, or validation workflows, creating unsafe deployment and governance decisions.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The method claims to enable automatic self-improvement, but it only sets a boolean flag and prints configuration status. This is dangerous because downstream users may assume autonomous code evolution and safety checks are active when no such controls exist, leading to misplaced trust in a high-risk capability area.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The example states that the night cycle runs automatically every night and that self-improvement is operational, but execution requires manual invocation and only simulates research and testing. In the context of an agentic AI skill advertising self-improvement and security gates, these claims can cause users to overestimate the maturity, autonomy, and safety of the system.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The README explicitly promotes self-rewriting and overnight research/update cycles, but does not pair those claims with clear user-facing warnings, approval requirements, rollback controls, or boundaries on what can change autonomously. In an agent framework, autonomous modification materially increases supply-chain, integrity, and operational risk because users may deploy a system that changes behavior after installation without informed consent.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README markets native MCP/A2A connectivity and access to 10,000+ production servers as a benefit, but omits clear warnings about data exposure, credential scope, remote action risks, and the possibility of high-impact operations across connected systems. In this context, broad connectivity makes the omission more dangerous because users may underestimate that an agent can reach sensitive infrastructure and act on it at scale.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly claims it will scan the external ecosystem nightly, test integrations, and propose or enact self-updates, but it does not present a clear consent gate, scope limitation, or warning about autonomous outbound activity and code changes. In a skill intended for direct installation and activation, this creates a meaningful risk of unreviewed network activity, supply-chain drift, and unauthorized modification of agent behavior over time.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The quick-start path tells users to activate a council that is described elsewhere as persistent and 24/7, yet it does not prominently warn that this may create continuous execution, background activity, network usage, and ongoing cost or system impact. Presenting persistent autonomous behavior as a simple one-line startup command increases the chance that users enable long-lived processes without understanding runtime, resource, or security consequences.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.