Back to skill

Security audit

cybersecured-agent-risk-advisory

Security checks across malware telemetry and agentic risk

Overview

The skill appears purpose-aligned for an AI-agent risk advisory service, but it asks the agent to collect and transmit sensitive environment and security details with weak consent and scoping safeguards.

Review this carefully before installing. Only use it if you are comfortable sending detailed agent-environment and security assessment data to the service provider, avoid running metadata probes or SSL-bypass test commands in production, and make sure the stored API key file is protected or removed with logout when no longer needed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The guide explicitly instructs the agent to probe cloud instance metadata services and environment details to infer deployment context. Metadata endpoints are highly sensitive in cloud environments and probing them is unnecessary for a questionnaire unless the user has explicitly supplied that information, so this creates environment-reconnaissance behavior and may expose credentials or infrastructure details.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
The questionnaire asks the agent to inspect authentication methods, API keys, password policy, and key-rotation practices. This goes beyond what is needed for application assistance and encourages collection of sensitive security configuration that could materially aid an attacker if exposed, especially because the skill is framed as a service-application helper rather than a dedicated security audit tool.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The guide directs the agent to enumerate installed plugins, identify malware scan results, and determine whether services are publicly exposed. Combined, these items form a useful reconnaissance profile of the environment that exceeds the minimal data needed for an insurance/service questionnaire and can reveal exploitable attack surface.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger list includes broad everyday phrases such as buying insurance, checking status, and refreshing status, which can cause the skill to activate in contexts the user did not intend. Because this skill collects security, identity, and incident information and may drive backend actions, unintended invocation increases the chance of unnecessary data collection or accidental workflow initiation.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
This section instructs the agent to gather detailed incident data, including security event descriptions, affected resources, root-cause hypotheses, mitigation actions, and loss amounts, and then submit them through the CLI/backend without an explicit privacy or transmission warning. In the context of breach and claims handling, these details are highly sensitive and could expose credentials, internal topology, customer impact, or regulated data if users are not clearly informed before collection and submission.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The authentication flow tells the user to provide an API key and states that the CLI stores configuration locally, but it does not clearly warn about local credential persistence, storage location, or handling precautions. In a security-focused skill, silent local storage of a bearer-style API key can lead to credential theft or misuse by other local users, malware, logs, or backups.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The document tells the agent to inspect the environment and potentially access cloud metadata endpoints without any warning about privacy, consent, or security consequences. Even if the goal is classification, active probing can touch sensitive interfaces and normalize unsafe behavior by the agent in environments where such access should never be attempted automatically.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The guide instructs the agent to inspect auth methods, API-key usage, password rules, and rotation settings without warning that these checks may reveal secrets or internal security controls. This is dangerous because it encourages sensitive configuration discovery in a non-audit workflow, increasing the chance of overcollection and leakage of privileged operational data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
This section directs the agent to collect highly identifying environment details such as platform IDs, absolute workspace paths, config file locations, network boundary, authentication methods, and deployment metadata. Even if intended for risk assessment, aggregating these fields without an explicit privacy notice, minimization guidance, or user-confirmation step increases exposure of sensitive operational metadata that could aid fingerprinting, targeting, or later compromise.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
This section instructs generation of concrete security findings about real configuration weaknesses and asks for specific descriptions of where they were found and why they matter. In the context of an insurance/risk-advisory skill, these outputs could concentrate exploitable weaknesses into a single artifact that may be stored, transmitted, or reviewed by third parties, materially increasing attack value if exposed.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
This section directs identification of credentials and important assets, and although it says not to output secret values, it still encourages structured enumeration of credential types, services, databases, and infrastructure. A consolidated inventory of what credentials and privileged systems exist is highly sensitive reconnaissance data and should not be collected or shared without strong handling safeguards.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.exposed_resource_identifier

Plaintext HTTP endpoint targets a CGNAT/Tailscale-range address.

Critical
Code
suspicious.exposed_resource_identifier
Location
references/questionnaire-guide.md:117