Back to skill

Security audit

anti-fraud

Security checks across malware telemetry and agentic risk

Overview

This anti-fraud skill is mostly defensive, but its training workflow asks the agent to generate realistic scammer scripts and adaptive pressure lines that could be misused.

Install only if you specifically need controlled anti-fraud training. Avoid using the drill to generate deployable scam scripts; prefer analysis, red-flag annotation, and safe response practice. The defensive detection and emergency guidance are coherent, but the roleplay workflow deserves careful review before use in a general assistant.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
This file explicitly instructs the agent to roleplay a scammer and produce realistic诱导话术, including pressure tactics, which materially enables social-engineering abuse. Although framed as anti-fraud training, the content meaningfully diverges from the anti-fraud manifest and lowers the barrier for generating operational scam scripts.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The skill is not merely describing scams; it tailors persuasion to audience level and generates second-round counter-objection pressure, which directly supports iterative fraud operations. In the anti-fraud context this is more dangerous, because users may trust the skill branding while obtaining optimized scam language under the guise of training.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The README states that the skill will proactively intervene whenever conversation contains terms like transfers, verification codes, screen sharing, unknown links, or impersonation cues, but it does not define contextual limits or suppression rules. This can cause unsolicited security warnings in benign conversations, creating over-triggering, alert fatigue, and possible disruption of unrelated tasks or user trust.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The phrase 'automatically insert sniffing when risk trigger words appear' explicitly enables behavior based on keyword presence alone, without documented boundary conditions, opt-out logic, or false-positive controls. In a conversational agent, this can be exploited or accidentally triggered to derail normal interactions, inject irrelevant warnings, or condition users to ignore genuinely important alerts.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The file says it is for anti-fraud educational simulation, but it lacks a strong, explicit warning that it generates realistic scam persuasion content that could be misused. Because the content already includes high-risk social-engineering capabilities, weak disclosure and framing increase the chance of accidental or intentional abuse.

Ssd 4

High
Confidence
95% confidence
Finding
The workflow explicitly instructs a 'fraudster' role to generate realistic scam scripts, then adapt them after seeing a simulated user's response with a second round of targeted pressure. That staged attacker→user→attacker loop meaningfully improves persuasive scam tradecraft, even though it says not to request real information, because it still teaches how to overcome resistance and refine social-engineering tactics.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.