Back to plugin

Security audit

Principles Disciple

Security checks across malware telemetry and agentic risk

Overview

The plugin’s governance behavior is mostly disclosed and purpose-aligned, but it automatically grants itself conversation-hook access and persistently records/influences agent behavior, so users should review it carefully before installing.

Install only if you want a local governance layer that can read conversation/tool-hook data, write local state, and influence future prompts/tool calls. Review the automatic allowConversationAccess change, switch the language to en if needed, and use the documented rollback/disable/export controls to monitor and reverse behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
83% confidence
Finding
The skill’s declared trigger scope excludes general programming and unrelated workspace tasks, but its interaction flow introduces a broader 'workspace cleaning' option that is not covered by the documented boundaries. This scope drift can cause the agent to activate outside intended conditions, increasing the chance of inappropriate guidance or unintended actions under a misleadingly narrow description.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The skill content is written entirely in Chinese and directs the agent to produce a structured execution report in Chinese, without any indication that language should follow the user's preference. This can override user expectations, reduce transparency for users or reviewers who do not read Chinese, and make security-relevant implementation actions harder to audit.

VirusTotal

1/61 vendors flagged this plugin as malicious, and 60/61 flagged it as clean.

View on VirusTotal

Static analysis

Detected: suspicious.env_credential_access

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/bundle.js:2
Evidence
var l7t=Object.create;var Mne=Object.defineProperty;var p7t=Object.getOwnPropertyDescriptor;var d7t=Object.getOwnPropertyNames;var m7t=Object.getPrototypeOf,f7t...