Back to skill

Security audit

Skill 发现中心

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a small skill-discovery demo, but it misleadingly claims successful installs and management features it does not actually perform.

Review before installing. This does not show evidence of credential theft, exfiltration, or destructive behavior, but its user-facing claims are not truthful: installs are simulated, favorites cannot be saved, recommendations are static, and the JavaScript file is currently syntactically invalid due escaped operators.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill advertises an install capability and returns a success message, but the implementation performs no installation at all. This is a deceptive or misleading behavior issue rather than code execution risk, but it can cause users or downstream agents to falsely believe software was installed and act on an incorrect system state.

Intent-Code Divergence

Low
Confidence
91% confidence
Finding
The UI tells users they can favorite skills after viewing details, but there is no code path that ever adds entries to the favorites list. This creates inconsistent state and misleading functionality, which can undermine trust and cause users or automations to rely on nonexistent persistence.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill advertises history tracking, favorites, personalized recommendations, and install/uninstall actions, which imply collection of user activity data and potentially system-affecting operations. Because the documentation does not disclose what data is stored, how long it is retained, whether recommendations are profile-based, or what safeguards/confirmation steps exist for installation actions, users may be exposed to privacy risks and unintended changes.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.