Back to skill

Security audit

skill-usefulness-audit

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local audit tool for reviewing installed skills and writing optional reports, with no evidence of hidden deletion, network exfiltration, persistence, or credential misuse.

Install only if you are comfortable letting it read your installed skill folders and any usage or history files you explicitly provide. Treat its delete or quarantine labels as review prompts, not automatic removal instructions, as the skill itself also states.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Lp3

Medium
Category
MCP Least Privilege
Confidence
90% confidence
Finding
The skill invokes a bundled Python script that reads local skill directories and optional evidence files, writes reports, and may access environment settings; the metadata also does not declare permissions despite these capabilities being present. This creates a transparency and least-privilege issue: hosts or reviewers cannot reliably understand or constrain what the skill can access, increasing the risk of unintended file, shell, or network use during execution.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.