Back to skill

Security audit

Expert Mode

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed project-advisory helper that may read project notes and create local expert roster/dossier files, with no evidence of hidden credential use, exfiltration, or destructive behavior.

Install this only if you are comfortable with a project-local advisory skill reading project notes and creating or updating experts/roster.md and experts/dossiers/*.md. Ask the agent to confirm before making any file changes outside the experts/ folder, and periodically review generated dossiers for stale, sensitive, or overly influential content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (10)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill explicitly instructs the agent to read and create project-local files such as `experts/roster.md` and `experts/dossiers/*.md`, and references helper scripts that write and validate files, yet the metadata declares only a binary requirement and no permissions. This creates a permission-transparency gap: users and enforcement layers may not realize the skill can modify workspace content, increasing the chance of unexpected file writes or policy bypass through implicit capabilities.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill is presented primarily as an interactive expert-advisory system, but its documented behavior also includes project maintenance operations such as generating dossier files, validating filesystem structure, and invoking helper scripts. That mismatch can cause users to activate a seemingly conversational skill that performs persistent local changes or broader project inspection, which is risky because consent and safeguards are framed around advice rather than tooling actions.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The examples instruct the agent to create and update multiple project files, which expands the skill from advisory analysis into persistent repository modification. That mismatch increases the chance that a casual 'expert mode' activation triggers unintended writes, especially if users expect review-only behavior from the manifest description.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
This custom expert flow persists knowledge by creating or updating roster and dossier files, but that side effect is not clearly bounded in the advisory-oriented description. Persistent modification of project knowledge can be exploited to plant prompt material, alter future behavior, or create durable state changes from what appears to be a consultation request.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger phrases are extremely broad, covering generic requests like technical analysis, design review, risk audit, second opinions, planning support, and advisor-style help. Overbroad activation criteria increase the likelihood that this skill is invoked in unrelated contexts, where it may start inspecting project files, creating rosters/dossiers, or steering responses through persistent archetype logic without the user intentionally requesting those side effects.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The workflow expands activation beyond the explicit trigger phrase to broad conditions like asking for expert perspectives or professional lenses. This can cause the skill to activate in unintended contexts, silently changing system behavior, loading extra project context, or creating files when the user did not clearly request expert-mode orchestration.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The trigger list includes broad natural-language phrases like 'add a <expert> expert' and 'bring in a <role/lens/stakeholder>', which can be matched during ordinary conversation rather than an intentional mode switch. This increases the risk of unintended activation, causing the agent to enter a different behavior mode, create artifacts, or produce expert-role outputs without clear user consent.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The trigger phrase 'Try use expert mode on this project' is broad and underspecified, making activation likely during ordinary discussion or review requests. In a skill that can read project files and potentially write new ones, ambiguous invocation increases the risk of unintended scope expansion and side effects.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The example trigger 'activating expert mode — review this README for clarity' overlaps with common editing or review requests, so the skill may activate when a simple non-skill response was intended. Because this skill context includes dynamic archetype loading and examples of file operations elsewhere, accidental activation is more dangerous than in a purely passive advisory tool.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger phrase "expert mode" is very generic and likely to appear in ordinary conversation, which can cause the skill to activate when the user did not intend to invoke it. In an agent system, unintended activation can change response style, context loading, and tool/skill routing, increasing the chance of prompt confusion, policy bypass via misrouting, or unnecessary exposure of project-specific context.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.