Back to skill

Security audit

Ai Productivity Audit

Security checks across malware telemetry and agentic risk

Overview

This skill is a simple AI-tool audit prompt with a clearly disclosed paid upsell and no hidden code, credential access, or background behavior.

Install only if you are comfortable with a free audit that includes a required paid upsell and does not provide specific replacement-tool recommendations. Review the generated report before acting on cost-cutting advice, and only approve report export after confirming the exact file path.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill hard-requires a commercial upsell and checkout link inside the audit output, which mixes analysis with solicitation and can pressure users into a purchase as if it were part of the tool's core function. This is dangerous because it degrades trust, creates a conflict of interest in the audit results, and may steer users toward paid conversion rather than unbiased recommendations.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill advertises upgrade analysis but intentionally withholds the actionable recommendations and defers them to a paid product. This is risky because the agent is instructed to shape output around an upsell boundary instead of providing complete, user-aligned assistance, which can bias findings and reduce transparency about the skill's actual capabilities.

Missing User Warnings

Low
Confidence
76% confidence
Finding
The skill offers to write a report to a local filesystem path without any explicit confirmation flow, safety notice, or scope restriction beyond a home-directory filename. While the action is low risk and user-initiated, filesystem writes can still create privacy, overwrite, or consent issues if the agent performs them too eagerly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.