Back to skill

Security audit

Kechuang Collection

Security checks across malware telemetry and agentic risk

Overview

This skill is a coherent public-information monitoring helper, with some disclosed local file output and an overclaimed monitoring workflow users should understand before use.

Install only if you are comfortable with the agent searching public web sources and saving lead reports/logs locally. Treat the background monitor and notification claims as under-specified unless your environment explicitly supports those tools, and periodically review or delete the leads-output files if using a shared machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill’s documented execution flow claims use of CronCreate and PushNotification even though those capabilities are not declared in allowed-tools. This mismatch can mislead reviewers and users about what the skill is permitted to do, and in some agent frameworks undocumented capabilities may encourage unsafe assumptions, overbroad implementations, or hidden future expansion toward background execution and notifications.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill states that scan results and monitor logs will be written to local directories, but this persistence is not prominently disclosed in the main usage flow before execution. Users may unknowingly create retained local artifacts containing collected URLs, summaries, and monitoring history, which can create privacy, operational, or disk-hygiene concerns on shared systems.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.