Back to skill

Security audit

Winskill

Security checks across malware telemetry and agentic risk

Overview

This Windows admin skill is mostly purpose-aligned, but its safety claims understate broad and sometimes mutating server operations.

Install only if you intend to use it for deliberate Windows administration. Treat cleanup, service, IIS, logging, and collector actions as privileged changes; require an explicit preview and confirmation, and do not rely on its blanket claims that it is purely read-only, fully offline, or avoids system directories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill repeatedly claims it is fully offline, yet it documents operations that may require network access, including installing IIS management features and updating the skill via a package manager. This mismatch can mislead users and downstream agents into making incorrect trust decisions about connectivity, change control, or data exposure assumptions.

Description-Behavior Mismatch

Medium
Confidence
98% confidence
Finding
The manifest and description emphasize '只读分析', but the skill includes state-changing actions such as deleting files, stopping/starting services, clearing caches, renaming files, and restarting IIS. A user or agent relying on the manifest could invoke the skill under the false assumption that it is non-destructive, increasing the chance of unintended system changes.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The security statement says system directories such as C:\Windows are never operated on, but later modules explicitly scan and clean within C:\Windows\Temp, C:\Windows\SoftwareDistribution, C:\Windows\Prefetch, and related paths. This contradiction undermines safety guarantees and could cause an agent or operator to authorize risky operations in sensitive system locations based on false assurances.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill advertises broad natural-language triggers like asking for help with disk scans, cleanup, IIS health, or errors in very generic phrasing. Such high-collision prompts increase the chance that an agent invokes this skill unintentionally during ordinary conversation, potentially exposing administrative context or initiating sensitive workflows.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Several example utterances are generic support phrases that overlap with normal troubleshooting requests. In systems with automatic skill routing, this can cause the skill to activate outside intended admin scenarios and lead to unnecessary access to logs, services, files, or system state.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The FAQ recommends very broad phrases like asking to scan a disk or check services, without constraints that this is a privileged Windows server operations skill. This increases accidental routing risk and could bring administrative actions into unrelated support conversations.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The quick-reference table contains short, ambiguous trigger phrases like '服务器卡', '检查服务', and '谁在连我' that are likely to collide with ordinary assistant requests. In an automated orchestration environment, these phrases could invoke a privileged ops skill more often than intended.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.