Back to skill

Security audit

skill-subtraction

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local audit tool for installed AI skills; it reads skill metadata and only archives or uninstalls after explicit confirmation.

Before installing, be aware that the skill will enumerate local installed skills and report names, paths, descriptions, sizes, and modification times. Review any keep/archive/uninstall recommendations yourself, especially where usage or business relevance is inferred, and only approve cleanup actions you actually want performed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
93% confidence
Finding
The skill claims broad auditing, scoring, deduplication, and recommendation capabilities that the underlying implementation reportedly does not perform. This can mislead users into trusting incomplete audit results, causing bad cleanup decisions or a false sense of security about their installed skills.

Description-Behavior Mismatch

Low
Confidence
80% confidence
Finding
The documented behavior says it scans only the current platform, but when autodetection fails it silently broadens scope to all installed agent platforms. In a privacy-sensitive environment, this can collect metadata from unrelated skill ecosystems without explicit user intent, increasing information disclosure beyond the expected boundary.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The README advertises very broad natural-language trigger phrases such as 'Clean up my skills' and 'Audit my installed skills', which increases the chance the skill auto-activates during ordinary conversation or when a user is discussing skills conceptually rather than requesting this specific tool. Because this skill scans installed skills across platforms and may progress toward archive/uninstall actions after follow-up confirmation, unintended activation can expose environment metadata and steer the session toward sensitive management operations.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The documented trigger phrases are very broad, natural-language requests such as checking installed skills, cleaning up skills, or auditing skills. Because these overlap with common conversational requests, the skill may invoke when the user did not intend to run this specific workflow, leading to unnecessary enumeration of installed skills and potentially sensitive local metadata exposure across platforms.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger language is extremely broad and overlaps with many ordinary requests about checking, listing, or cleaning skills, increasing the chance the skill activates when the user did not intend a cross-platform audit. Unnecessarily broad activation can expose local skill metadata and filesystem structure beyond what the user expected for a simple request.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.