Back to skill

Security audit

Roundtable Forge

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed roundtable-discussion orchestrator whose file writes, scripts, web checks, and optional subagents fit its stated purpose.

Install if you want a structured, Chinese-friendly multi-character roundtable workflow that creates local Memory and Markdown artifacts. Review the broad trigger phrases and language defaults if you prefer explicit invocation only, English output, or no local artifact generation.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (12)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs the host to read and write files and invoke shell-backed scripts, yet it declares no permissions. That mismatch can cause the platform or reviewer to underestimate its effective capabilities, which weakens security review and increases the chance of unintended filesystem or command execution in deployment.

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The public description frames the skill as a discussion router, but the body also performs validation, artifact generation, rendering, and script execution workflows. This gap can mislead operators and users about the skill's actual attack surface, making risky behaviors like filesystem access and shell-backed processing less likely to receive appropriate scrutiny.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The trigger cues include broad, everyday phrases such as requests for more depth or other perspectives, which can activate the skill when the user did not intend a multi-agent workflow. Unintended activation matters here because the skill may create files, route execution, and invoke additional tooling, expanding processing beyond user expectations.

Vague Triggers

Medium
Confidence
88% confidence
Finding
Several trigger phrases are generic conversational requests such as asking for analysis from different angles or a roundtable discussion. In a skill-routing environment, these broad triggers can cause unintended activation of this skill for ordinary prompts, leading to misrouting, unnecessary multi-agent orchestration, and possible expansion of generated content beyond what the user explicitly requested.

Vague Triggers

Low
Confidence
89% confidence
Finding
The usage guidance includes broad activation language such as using the checklist as a general roundtable starting point, but it does not clearly define when the skill should or should not be invoked. In a multi-agent orchestration context, ambiguous triggers can cause the skill to activate in unintended scenarios, leading to off-topic behavior, policy drift, or over-application of a specialized checklist to unrelated user requests.

Natural-Language Policy Violations

Medium
Confidence
88% confidence
Finding
The protocol includes hard-coded Chinese-language conductor prompts and examples without indicating that output should follow the user's language or a configurable locale. In a multi-agent orchestration skill, this can cause language-mismatch behavior, reduced usability, and unsafe misunderstandings if users interpret forced-language output as authoritative despite not fully understanding it.

Natural-Language Policy Violations

Medium
Confidence
92% confidence
Finding
The template mandates appending a Chinese-only disclaimer to every output, regardless of the user's language or locale. In a multi-agent discussion skill, this can mislead or exclude users who cannot read the disclaimer, reducing transparency about AI-generated and impersonation-sensitive content.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The trigger cues for `six_hats` include broad phrases such as '全面分析', '从多个维度', and '结构化讨论', which are common ways users ask for general analysis rather than an explicit methodology. In a routing protocol, this can cause unintended activation of a more prescriptive discussion structure than the user intended, leading to misrouting, loss of user intent fidelity, and potentially misleading outputs.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The `fishbone` trigger list includes generic phrases like '多套方案', '分组讨论', and '交叉评审', which can appear in ordinary collaboration requests without meaning the Fishbone structure. This creates a prompt-routing weakness where normal user requests may be overfit to a specialized structure, reducing reliability and making agent behavior less predictable.

Natural-Language Policy Violations

Medium
Confidence
89% confidence
Finding
The protocol explicitly mandates Chinese-language phrasing (for example, requiring conversational fillers like Chinese expressions) and Chinese-market distribution conventions in the output format, without indicating that this behavior is conditional on user locale or preferences. This can override user intent, cause unwanted disclosure on region-specific platforms, and produce culturally or legally mismatched output when the skill is used outside its intended market.

Vague Triggers

Medium
Confidence
80% confidence
Finding
The main route trigger is described in broad natural-language terms ('user wants a multi-character discussion or cross-disciplinary analysis'), which can cause overmatching and unintended invocation. In a routing table, ambiguous triggers can misroute unrelated requests into a multi-agent workflow, increasing the chance of inappropriate persona simulation, policy bypass via wrong tool selection, or unnecessary processing of sensitive topics.

Vague Triggers

Medium
Confidence
84% confidence
Finding
Referencing a generic `roundtable`/`召集` summon signal without a concrete allowlist or decision rule leaves routing behavior open-ended. This ambiguity can be exploited by prompt phrasing to steer the system into this skill even when the request is out of scope, weakening routing isolation and making downstream safety controls less reliable.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dynamic_code_execution

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
scripts/run_eval_fixture.py:24