Back to skill

Security audit

dev-expert

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent developer-assistant package, but it needs Review because it can persist or externally publish sensitive project details without clear opt-in, destination, or redaction rules.

Install only if you are comfortable with a broad coding assistant that may read project context, modify or create files for development tasks, and preserve project details across sessions. Treat Notion/export use as opt-in only: confirm the destination, review the content, and remove secrets, credentials, customer data, internal URLs, and deployment/account handoff details before allowing any external write.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (35)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill expands from API design into persistence and external synchronization by instructing the agent to record design decisions into project memory and potentially local files. This creates an unnecessary data-retention and exfiltration surface: API designs often contain internal architecture, auth choices, endpoints, and integration details that should not be persisted or exported without explicit user consent and clear scope boundaries.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Allowing the skill to write API design documents to Notion introduces an external write channel unrelated to the minimum necessary function of designing APIs. If triggered in a real environment, sensitive implementation details could be sent to a third-party workspace, causing confidentiality, compliance, and change-control issues.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill explicitly allows writing CMS development records and configuration to Notion, an external service, even though this is not necessary to perform CMS secondary-development guidance. That creates a real data-exfiltration and privacy risk because project architecture, credentials-adjacent configuration, or internal file paths may be persisted outside the working environment without explicit user approval.

Description-Behavior Mismatch

Low
Confidence
84% confidence
Finding
The file directs the agent to record CMS type, version decisions, table conventions, and security measures into project memory or local files, extending behavior beyond transient development assistance. While likely intended for continuity, this persistence can retain sensitive operational details without clear user awareness or consent.

Context-Inappropriate Capability

Medium
Confidence
78% confidence
Finding
Declaring the ability to write review reports and remediation checklists into Notion introduces an external write channel unrelated to the minimum necessary act of analyzing code. In a code-review context, findings often contain proprietary source snippets, security issues, or secrets, so sending them to a third-party knowledge system can cause unintended data disclosure or compliance violations if not tightly controlled.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as document generation, but it also instructs the agent to persist derived information into project memory, which expands behavior from content creation into stateful data storage. That creates a scope-creep risk: sensitive project details, architectural decisions, or internal conventions may be retained or propagated without explicit user consent, increasing the chance of unintended disclosure or persistence.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
Allowing the skill to write generated documents to Notion gives it outbound data-transfer capability beyond its core purpose of producing documentation text. If used on proprietary code or internal architecture, this can exfiltrate sensitive information to an external SaaS destination, especially when the transfer is implied as an enhancement rather than a separately authorized action.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill instructs persisting specifications and design decisions to project memory even though the core function is requirements/spec alignment. That creates an unnecessary data-retention side effect and may store sensitive project details without explicit user consent, increasing privacy and data-governance risk.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The fallback behavior instructs writing Spec and Design to a local file when project memory is unavailable, expanding the skill from drafting guidance into filesystem modification. Silent file creation can leak sensitive requirements to disk, violate user expectations, and create persistence artifacts in unsafe locations.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The optional Notion connector includes writing requirement documents to an external SaaS platform, which goes beyond local spec drafting and may transmit confidential project information outside the user's environment. Without explicit consent and data-classification checks, this can cause unintended data disclosure.

Context-Inappropriate Capability

Medium
Confidence
84% confidence
Finding
The skill explicitly advertises a Notion connector that can write task decomposition plans into an external knowledge base, extending the skill from local planning into data exfiltration and persistent publication. Because task plans may contain internal architecture, deployment details, credentials-by-reference, or sensitive operational context, enabling outbound writes without strict scope, consent, and sanitization creates a real security risk.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The document is presented as a technology-selection template, but it also instructs the agent to persist decisions to project memory, local files, or Notion. That crosses from analysis into side-effectful actions, which can cause unintended data exfiltration, unauthorized writes, or durable storage of sensitive architectural information if the skill is invoked in a broader agent environment with connectors enabled.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill expands from generating test cases into persisting derived project information in a cross-session memory store. That creates an unnecessary data-retention side effect: source-derived testing strategy, mocks, and coverage baselines may include sensitive implementation details and be written beyond the user's immediate request, increasing confidentiality and scope-creep risk.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The fallback behavior instructs the skill to write test strategy data to a local file when the project memory system is unavailable, introducing an unrequested filesystem side effect. Local persistence can leak sensitive codebase structure, security testing plans, or internal coverage notes into files that may be committed, shared, or accessed by other processes.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
The optional Notion connector allows test coverage reports to be sent to an external knowledge base, which is outside the core function of generating tests. Even if framed as an enhancement, exporting source-derived test artifacts to third-party services can expose internal architecture, risk areas, and security-relevant implementation details to external systems without strong necessity.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README states that users can 'naturally trigger' skills and have them 'automatically matched,' but it does not describe tight routing constraints, confirmation steps, or disambiguation. In a broad developer-assistant skill pack, this can cause unintended activation of powerful subskills based on casual conversation, leading to incorrect actions, unsafe guidance, or unexpected handling of sensitive project context.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger keyword lists include many generic terms such as 'debug,' 'SQL,' 'README,' '实现功能,' and '做网站' that are common in ordinary developer dialogue. Because the skill is a high-scope orchestration package spanning code generation, review, deployment, database, and memory functions, overlapping keywords increase the chance of misrouting into an unintended subskill and can amplify downstream security or privacy mistakes.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The routing keywords are extremely broad and cover common development phrases such as 写代码, 实现功能, debug, SQL, and UI-related terms. This can cause the skill to activate or route into powerful sub-skills on ordinary prompts without clear user intent, increasing the chance of unintended actions or overbroad instruction application.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The routing logic permits matching based on vague 'scene' descriptions in addition to explicit keywords, and falls back to choosing the 'highest match' when multiple skills overlap. In a multi-capability coding skill, this ambiguity can misroute user requests into workflows that read templates, generate artifacts, or perform broader actions than the user intended.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill instructs the agent to write generated files and then declare outputs, but it does not require user consent, path scoping, or safe-write boundaries. In practice, this can lead to unintended modification of workspace files, overwriting user content, or creation of artifacts in unsafe locations if the routing or downstream template is triggered incorrectly.

Missing User Warnings

Low
Confidence
84% confidence
Finding
The skill recommends using external web_search/web_fetch tools to obtain outside data or services, but it does not warn that task context, code, or sensitive project details may be transmitted to network-accessed systems. In a development assistant context, prompts often contain proprietary source code, credentials, architecture details, or incident data, so silent network use creates a confidentiality risk.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill describes writing artifacts to local files and external systems but does not present an explicit warning, consent step, or data-handling disclosure. That omission increases the chance of silent leakage of internal specifications, credentials-by-reference, or business-sensitive design material into persistent or shared locations.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs storing CMS development records to local files or project memory without a user-facing disclosure that project data will be persisted. This is dangerous because even seemingly routine configuration notes can include sensitive stack details, internal paths, or security-relevant decisions that increase exposure if retained unexpectedly.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The optional Notion connector advertises writing CMS documents and configuration to an external SaaS platform without any warning about data sharing, sensitivity, or approval requirements. In a development context, this can expose internal system design, plugin structure, database conventions, and other confidential implementation details to third-party storage.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill states that generated code and design documents may be written to Notion, but it does not mention user consent, data sensitivity checks, or external transmission warnings. In a code-generation context, outputs may contain proprietary source, credentials, internal architecture, or customer data, so silent or implicit export to a third-party service creates a real confidentiality risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.