Back to skill

Security audit

hekouwang-claude-skill-doctor-skill

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed SKILL.md quality checker with local scanning scripts that fit its stated purpose.

Install this if you want a local SKILL.md/Agent Skill linting workflow. Be aware that optional trigger evaluation calls the Claude CLI and can cost money, and the suite script expects related doctor skills in your local skills directory; review those commands before running them on broad directories.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
69% confidence
Finding
The skill declares an extremely broad trigger scope: it should activate for essentially any request about evaluating, auditing, or optimizing an Agent Skill. Overbroad auto-invocation can cause the model to load this skill in unrelated contexts, increasing prompt surface area and potentially crowding out more specific skills or causing unintended file inspection guidance to run.

Vague Triggers

Low
Confidence
88% confidence
Finding
The trigger text is intentionally broad enough to activate on almost any request about reviewing or optimizing an Agent Skill, which can cause over-invocation and unintended routing. In a security-sensitive skill ecosystem, ambiguous activation criteria increase the chance that this skill runs on irrelevant inputs, potentially exposing project content to unnecessary analysis steps or causing policy-confused behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.