Back to skill

Security audit

Seed

Security checks across malware telemetry and agentic risk

Overview

This skill is not deceptive, but it gives an agent powerful remote firmware-control authority with weak guardrails around live changes and bearer-token exposure.

Install only for devices you own or are authorized to administer. Keep the node on a trusted network, protect and rotate the bearer token, review generated firmware before applying it, verify the downloaded source, and test on non-critical hardware before using it on anything important.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This skill explicitly guides an agent to upload, compile, and hot-apply new firmware to a target device, which is a high-risk system-modification capability. Although framed as intended functionality, the skill lacks strong user-consent gates, safety warnings, target-ownership verification, or constraints on what firmware may be deployed, making unauthorized or harmful device changes easier.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill instructs users to retrieve full connection details and a bearer token over HTTP, and even notes that the token can be obtained via `/skill`. Exposing secrets over unauthenticated or plaintext channels creates a serious credential-leak risk, especially on local networks where interception or accidental disclosure could grant full control of the node and its firmware.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.