Back to skill

Security audit

masterplan-builder

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed project-planning skill that researches, interviews the user, and writes a masterplan file, with a caveat that users should watch for unintended overwrites in docs/masterplan.

Install this if you want a full, file-backed project masterplan. Before running it in a repository with existing docs/masterplan content, check whether masterplan.md already exists or ask the agent to preview and confirm before writing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Vague Triggers

Medium
Confidence
86% confidence
Finding
The invocation examples are broad enough to overlap with many generic planning requests, which can cause the skill to trigger in contexts where the user did not explicitly consent to its full workflow. Because this skill performs multi-step interviewing, live web research, and writes output into the project directory, ambiguous activation increases the chance of unintended actions and scope overreach.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The description omits an upfront warning that the skill will create or overwrite a file under docs/masterplan/ in the user's project directory. Users may invoke the skill expecting only conversational planning help, but instead trigger filesystem modifications, which creates a consent and integrity risk in a development environment.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The skill description is extremely broad and includes common phrases like planning, building, or designing almost any kind of project. That can cause the skill to activate in situations where the user only wanted lightweight advice, leading to unnecessary file-writing, web access, and persistent project modifications without clearly bounded intent.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill explicitly instructs the agent to create directories and write files without asking first. In an agent environment, autonomous filesystem writes are risky because they can modify a repository, overwrite user work, or create unwanted artifacts when the user only expected a conversational planning exercise.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.