Back to skill

Security audit

Model Advisor

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a model-advice helper, but its reported auto-triggering and persistent preference recording are broader than users would reasonably expect.

Review this skill carefully before installing. Its model recommendations may be useful, but users should confirm whether it can be disabled, what preference data it stores, where it stores it, and how to delete it. Avoid installing it in sensitive workflows unless activation is narrowed to explicit model-selection requests and persistence is made opt-in.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill’s stated purpose is model recommendation, but it additionally instructs persistent storage of user preferences in a local memory file. This creates unnecessary data retention and scope expansion, which can expose behavioral data or sensitive task patterns without clear need, notice, or consent.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
The hard-coded path to a specific user directory is unjustified for a model-advisor skill and couples the skill to local filesystem state. This can lead to unauthorized writes, privacy issues, or unexpected behavior across environments, especially if the agent is permitted file access.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The README says the skill should trigger automatically for every new task and for broad model-related queries, which can cause unintended invocation across unrelated workflows. In a skill that influences model selection, over-broad auto-triggering can unexpectedly steer tasks to different models, increasing privacy exposure, cost, or operational confusion without clear user intent.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation states that the skill records user preferences but provides no explanation of what data is stored, where it is stored, how long it is retained, or whether users can disable it. Because the skill is explicitly used in privacy-sensitive task routing, undisclosed preference tracking creates a meaningful privacy risk and may leak behavioral or task-category metadata.

Vague Triggers

High
Confidence
93% confidence
Finding
The skill is configured to proactively trigger on nearly every new task, far beyond narrow model-selection requests. Overbroad invocation increases the chance that unrelated or sensitive user content is unnecessarily analyzed, which expands the skill’s reach and can interfere with normal task handling.

Vague Triggers

High
Confidence
96% confidence
Finding
Using a generic phrase like '帮我' as a trigger makes the skill match a huge portion of normal conversations. This causes excessive unsolicited activation, increasing data exposure and making the skill effectively omnipresent rather than purpose-limited.

Vague Triggers

Medium
Confidence
91% confidence
Finding
Mandating proactive execution at conversation start, task switches, and token-optimization moments lacks clear boundaries and opt-out controls. In context, this makes a benign advisory skill more invasive because it continually inspects workflow state and inserts itself into unrelated exchanges.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill instructs storing user preferences persistently without an explicit warning or consent flow. Even preference data can reveal sensitive habits, workloads, or privacy priorities, and undocumented retention increases privacy and compliance risk.

Ssd 3

Medium
Confidence
88% confidence
Finding
The instruction to record user feedback/preferences to persistent memory lacks minimization, consent, and retention controls. In a skill that only recommends models, persistent profiling is unnecessary by default and can accumulate sensitive preference history over time.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.