Back to skill

Security audit

Documentation

Security checks across malware telemetry and agentic risk

Overview

This is a local documentation-assistance skill with harmless stub scripts and no evidence of hidden network, payment, persistence, or destructive behavior.

Install this if you want a Chinese-language local documentation helper. It may read local project files when you ask it to work from them, but the reviewed artifacts do not show external upload, payment checks, credential use, persistence, or destructive actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding
This is a mismatch because the declared purpose describes a documentation-assistance skill, but the actual code does not implement any such functionality. Instead, it merely outputs informational status messages about the skill being free and locally runnable. There is no hidden harmful behavior or external access, but the primary purpose of the code materially differs from the described documentation support capability.

Natural-Language Policy Violations

Medium
Confidence
96% confidence
Finding
The instruction "请使用中文和用户交互" mandates a specific language for all interactions. This is a natural-language policy concern because the file does not offer the user a language choice, opt-in, or a documented region-specific justification for the restriction.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.