Back to skill

Security audit

Legal Settlement Evaluation Framework

Security checks across malware telemetry and agentic risk

Overview

This is a document-only legal settlement framework with no code execution or data access, though users should treat its specific settlement examples as informational and verify them with counsel.

Install only if you want a non-executable legal workflow aid. Treat its settlement examples, especially the specific compensation range in the traffic-accident scenario, as illustrative rather than legal advice, and verify jurisdiction-specific decisions with qualified counsel.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The example at L085-L087 recommends a negotiation range and discusses when acceptance may be reasonable, which is substantive advice on a settlement decision. This conflicts with the documented limitation at L096 that the skill 'does not predict court outcomes or advise acceptance' and that final settlement decisions require attorney-client analysis.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The manifest header declares `language: en` and the acceptance criteria say the package is "English-first," but Scenario 4 is entirely in Chinese. This creates a locale/language policy inconsistency because the skill includes a forced alternate-language example without documenting user opt-in or explaining a region-specific exception.

Natural-Language Policy Violations

Low
Confidence
95% confidence
Finding
The manifest sets the skill language to "en" with no indication that users can choose another language or that the skill is limited to an English-only context. This is a natural-language policy concern because it imposes a locale constraint without documented opt-in or justification.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.