Back to skill

Security audit

Tmp.3yfrh0Gbe7

Security checks across malware telemetry and agentic risk

Overview

The skill is a curl guide for Artsonia account access, but it also documents private artwork downloads without authentication and account-changing actions such as sending fan invites.

Install only if you are authorized to access the specific Artsonia account and student portfolios involved. Treat downloaded artwork, profile contact details, cookies, and invite actions as sensitive: avoid bulk downloads unless needed, protect or delete local files, and require explicit confirmation before posting comments, sending invites, marking feedback read, or changing notification settings.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill explicitly documents unauthenticated access to full-resolution artwork images and states this works even for 'private pieces'. That exposes student-associated content outside the authenticated member flow described by the skill and can enable privacy violations or bulk harvesting of images that users may reasonably believe are access-controlled.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
The documented capability goes beyond the stated purpose of using authenticated curl requests to access a user's Artsonia account data and instead highlights a way to fetch full-resolution images without authentication, including for private pieces. That materially increases the risk of misuse because it provides a direct recipe for bypassing expected privacy boundaries and collecting sensitive student artwork at scale.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documentation exposes authenticated write operations such as posting comments, inviting fans by email, marking feedback as read, and modifying profile notification settings, even though the skill is described primarily as a data-access mechanism. That scope expansion materially increases abuse potential because a user or downstream agent can perform state-changing actions on a school/student-art platform, including triggering outbound emails and altering account state.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The fan-invitation flow enables sending real invite emails to external recipients from an authenticated Artsonia account, which goes beyond passive portfolio access. This can be abused for unauthorized outreach, spam, social engineering, or exposing student associations to third parties, and the documentation even notes that it sends a real email.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill provides instructions for downloading images for 'private pieces' from a public CDN but omits any warning about privacy, consent, or downstream handling of student artwork. In the context of a student-art platform, failing to warn users about the privacy implications makes misuse more likely and normalizes access to content that may be sensitive.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The download instructions encourage saving and bulk-downloading student artwork images locally without any privacy, retention, or authorization warning. In the context of student portfolios, bulk export increases the chance of over-collection, uncontrolled redistribution, or storage of minors' content outside the original platform's access controls.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The profile-reading instructions retrieve and parse personal contact information including first name, last name, email, and mobile number, but do not warn that this is sensitive personal data. Because this skill targets parent/member pages on a student-art service, exposing easy extraction recipes for contact data heightens privacy and misuse risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.