Back to skill

Security audit

Df Merger

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a normal construction data-merging helper, with local file access that fits its stated purpose.

Install if you want help merging construction datasets. Provide only the specific files needed, review inferred or fuzzy matches before using outputs for cost or schedule decisions, and confirm any export path before writing results.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Missing User Warnings

Low
Confidence
93% confidence
Finding
The skill performs automatic fuzzy matching and inferred-key merges that can silently join unrelated records, especially with low thresholds and fallback to first-column matching. In construction workflows, incorrect joins can propagate into schedule, quantity, or cost outputs and cause materially wrong decisions without obvious runtime errors.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The instruction "When the user asks to assist with construction project tasks" is a broad natural-language activation condition that can cause the skill to trigger in situations beyond its intended dataframe-merging scope. This can lead to inappropriate invocation, confusion about tool boundaries, and unintended processing of user-supplied files or paths, especially since the skill advertises accepting multiple input formats and references additional implementation in SKILL.md.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.