Back to skill

Security audit

Agentcad Skill Release 0.4.0

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Fusion 360 furniture-modeling helper that uses local code execution to create CAD models, which is powerful but aligned with its purpose.

Install only if you are comfortable with a Fusion 360 add-in that can run generated local CAD scripts. Review the GitHub installer before running the curl-to-bash command, and keep backups of important Fusion documents because the skill can modify the active model during normal use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly instructs the agent to run `agentcad view` after every successful build, which opens a local file in the user's browser without prior consent. Automatic local side effects can surprise users, disrupt workflows, and expose local content or trigger downstream browser-handled behaviors that the user did not request.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.