Back to skill

Security audit

Doc Setup

Security checks across malware telemetry and agentic risk

Overview

This skill organizes documentation into structured Markdown notes and does not show hidden access, persistence, or unsafe behavior.

Install if you want help turning documentation into structured notes. Provide a specific source and destination folder, review proposed file changes before applying them, and avoid pointing it at private or secret-containing documentation unless you want that material summarized.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Tp4

High
Category
MCP Tool Poisoning
Confidence
89% confidence
Finding
The declared purpose focuses on organizing and summarizing documentation, but the skill also references auditing and validation behavior over an existing docs directory. That mismatch can cause the agent to perform broader inspection than the user expects, increasing the chance of unintended workspace enumeration or modification decisions based on files outside the intended documentation task.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger conditions are broad enough to activate on nearly any documentation-related request, which raises the risk of over-triggering the skill in contexts where file creation, reorganization, or external source extraction was not intended. Over-broad activation is dangerous because it can lead to unauthorized writes, unexpected source fetching, or premature restructuring of user content under an ambiguous request.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs creating and organizing numbered files in a directory structure but does not warn the user that it may write or modify files in the workspace. This lack of transparency creates a real safety issue because users may invoke the skill expecting analysis-only behavior, while the agent could generate, overwrite, or reorganize documentation artifacts.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.