Back to skill

Security audit

Smart Refinement System

Security checks across malware telemetry and agentic risk

Overview

This skill is a local prompt-refinement and skill-matching helper; it has some privacy documentation gaps but does not itself read private stores, send data out, or execute tools.

Safe to install for local prompt cleanup and skill suggestions. Treat its suggested tools as recommendations only, keep normal agent approval controls for command/file/network actions, and avoid passing secrets or sensitive project history as context unless you are comfortable with the host agent retaining it in memory during that session.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill explicitly advertises automatic integration of conversation history, project context, and operation records, but provides no disclosure, consent model, minimization limits, or handling guidance. In an agent setting, these data sources can contain sensitive user content, secrets, or internal project information, so silently aggregating them increases privacy leakage risk and can broaden the blast radius of prompt injection or unintended downstream disclosure.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation states that context integration data is automatically cached, but does not explain retention duration, scope, invalidation, or whether sensitive data may be stored in cache. Caching contextual data can preserve secrets or personal information longer than users expect and can expose that data to other components, operators, or later prompts if isolation is weak.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.