Back to skill

Security audit

SkillHub 管家

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed SkillHub manager, but it can implicitly trigger credential setup and broad skill-install/update flows that modify local agent behavior.

Install only if you intend this skill to manage Winmale credentials and modify local agent skill directories. Before running updates, confirm the catalog source is the official Winmale source, keep API keys out of chat logs and repositories, and prefer explicit user approval for any install, update_all, or credential rotation action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
93% confidence
Finding
The skill instructs the agent to perform sensitive operations including writing credential files, downloading remote packs, invoking shell scripts, and making authenticated network calls, yet no explicit permission model is declared. That mismatch is dangerous because a host or reviewer cannot reliably constrain execution, and the skill handles API secrets plus software installation/update flows that could modify the local environment.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The skill enables implicit invocation globally via `allow_implicit_invocation: true`, which increases the chance the agent will trigger this skill without an explicit user request or narrowly defined conditions. Because this skill is designed to manage API credentials and install or update other skills/roles, accidental or overly broad activation could expose sensitive setup flows or expand the attack surface for supply-chain style abuse.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.