Back to skill

Security audit

self-improving-analytics

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed local analytics learning logger with optional reminders, and I found no hidden exfiltration, destructive behavior, or automatic privileged changes.

Before installing, decide whether you want only local markdown logging or also persistent hooks. Keep hooks project-scoped, prefer the prompt reminder unless you specifically need Bash-output detection, redact secrets and PII from learnings, and review any proposed changes to AGENTS.md, TOOLS.md, MEMORY.md, hooks, or generated skills before approving them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (6)

Tp4

High
Category
MCP Tool Poisoning
Confidence
88% confidence
Finding
The skill is presented as an analytics learning/logging aid, but it also introduces bootstrap context injection, persistent hook activation, tool-output inspection, and skill scaffolding behaviors beyond that narrow purpose. This mismatch reduces informed consent and can cause users to enable broader automation and observation than they reasonably expected from the description.

Description-Behavior Mismatch

Medium
Confidence
85% confidence
Finding
The documented promotion flow expands the skill from local analytics logging into modifying or influencing broader control files such as AGENTS.md and TOOLS.md, which can affect future agent behavior. Even though the text says to show a reviewed diff and require approval, the capability broadens the trust boundary and could be abused to launder workflow changes through a seemingly harmless analytics skill.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Persistent hooks that inspect command output materially expand the skill's access to operational context and can capture sensitive data from tool runs, even if the documentation advises against logging secrets. Because hooks persist across sessions, accidental over-collection or repeated unsolicited activations can continue long after the original task.

Context-Inappropriate Capability

Medium
Confidence
80% confidence
Finding
Generating new skills from logged learnings creates a pathway from passive note-taking to producing executable agent instructions, which increases the chance that unreviewed or adversarial content is operationalized. The file does warn that extracted skills are untrusted until human review, but the capability still exceeds the stated logging purpose and can amplify mistakes across projects.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The matcher includes broad terms like 'metric', 'schema', and 'warehouse', which are common in ordinary engineering conversations and can trigger the skill unnecessarily. Overbroad activation increases noise, normalizes background monitoring, and may cause the hook to process unrelated prompts or data contexts.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The repeated broad matcher in advanced hook setup has the same problem of activating on generic analytics vocabulary, and in this case it pairs with additional PostToolUse behavior. This makes the context more dangerous because broad prompt interception can lead users into enabling downstream tool-output inspection too often.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.