Back to skill

Security audit

service-registry

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-style service registry guide whose external-service use is purpose-aligned, with minor review notes around broad triggers and privacy disclosure.

Before installing, confirm you want a skill that may guide agents to run configured external service CLIs and pass prompts or named files to those services. Use trusted services, review API key setup and service config, and avoid sending sensitive files unless the provider and account policy allow it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
96% confidence
Finding
The manifest trigger phrases include generic terms such as "services," "registry," "execution," and "integration," which are common in everyday technical conversation and are not narrowly scoped to this skill. Although one trigger is more specific, the overall trigger set lacks clear constraints or negative examples, increasing the chance of unintended invocation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The markdown shows examples where prompts and files are executed through external services, which can transmit user data off-system. The document describes the functionality but does not include a user-facing warning about privacy, data handling, or the implications of sending files and prompts to third-party services.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.