Back to skill

Security audit

Rule Toolkit

Security checks across malware telemetry and agentic risk

Overview

This skill has a legitimate rule-automation purpose, but it can rewrite authoritative agent rule files and create automatic mutating hooks, so users should review it carefully before installing.

Install only if you want an agent to generate enforcement tooling from project rules. Require a reviewed diff before any edits to CLAUDE.md, agents.md, soul.md, tools.md, bootstrap.md, .cursorrules, or Copilot instructions, and do not allow source-rule removal unless the generated tooling fully preserves the original intent. Review generated hooks as code that may run automatically and modify files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill instructs the agent to remove or replace rules in existing constraint files, which is a destructive modification to project guidance. Although later safety text says to show changes before writing files, there is no hard approval gate before editing source files, so an agent could silently alter governance documents and reduce future safeguards or auditability.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The cleanup section directs modification of existing project files without a prominent warning that these are source-of-truth constraint documents. In a security-sensitive workflow, replacing or removing rules can weaken controls, create drift between intent and enforcement, and make it harder to review what policy was originally in place.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.