Back to skill

Security audit

Axis

Security checks across malware telemetry and agentic risk

Overview

This skill has a legitimate admissions-advising purpose, but it asks for broad shell access and persistent student-profile storage while the package only includes instructions, not the referenced safe runner or data files.

Review before installing. This does not show malware or exfiltration, but it grants shell-command authority and stores student advising data locally. Install only if you trust the publisher and are comfortable with local session/report files; avoid sharing sensitive student details unless you understand where the workspace files will be saved and how to remove them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The skill exposes the broad `execute_bash` capability to an admissions-advising workflow and explicitly instructs the agent to use shell commands for routine state and reporting tasks. Because shell execution is far more powerful than the stated business need, prompt injection, path abuse, or future instruction changes could pivot this skill into arbitrary command execution against the host environment.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly supports saving, restoring, and listing student session data, which is likely to include personal academic profile information, without any user-facing notice, consent step, or retention boundary. This creates privacy and data-handling risk because users may disclose sensitive student data without realizing it will persist across sessions or be recoverable later.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill directs use of shell execution for backend operations without any user-visible warning that external commands may run as part of fulfilling the request. While the primary issue is overscoped tooling, the lack of transparency also matters because users cannot make an informed decision about interacting with a tool-enabled workflow that may touch local files or persistent state.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.