Back to skill

Security audit

女娲造人

Security checks across malware telemetry and agentic risk

Overview

This skill appears designed to create persona-style skills, but it can persistently write new agent skill files and perform online research without a clear separate consent step.

Install only if you are comfortable with a skill that can create persistent local skills and perform online research. Before using it, ask it to run in preview/local-only mode where possible, list exact files before writing, avoid sending private source material to external services, and review any generated skill before enabling it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Context-Inappropriate Capability

Low
Confidence
91% confidence
Finding
The skill explicitly instructs creating and writing files under .claude/skills before presenting research results, which expands behavior from analysis into local filesystem modification. That is risky because it can cause unintended persistent changes, overwrite existing content, or create artifacts without an explicit just-in-time user confirmation tied to the write action.

Context-Inappropriate Capability

Low
Confidence
87% confidence
Finding
The skill directs broad multi-agent external research across many sources and even defaults to network retrieval when local materials are absent. This creates a data-exfiltration and privacy risk because user prompts or attached materials could be propagated to external services, and it may trigger network activity beyond what users reasonably expect from a persona-distillation skill.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation text is extremely broad, covering generic requests such as building skills, distilling anyone, obtaining ways of thinking, or needing a thinking advisor. Overbroad triggers can cause the skill to activate in unrelated contexts, unexpectedly steering conversations into file creation, web research, or persona simulation workflows the user did not specifically request.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The instructions say to 'immediately execute' creation of a local skill directory and files after confirmation of the topic, but there is no separate warning that filesystem changes will occur. This is dangerous because users may think they are only discussing or researching a persona while the skill performs persistent local writes without a specific consent checkpoint.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The workflow defaults to network-based research when the user says 'just do XX' and no local corpus is provided, but it does not clearly warn that external retrieval will occur. Hidden default network access can expose user intent, gather third-party content unexpectedly, and violate user expectations about privacy and offline operation.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.