Back to skill

Security audit

Auto Model Router

Security checks across malware telemetry and agentic risk

Overview

This model-routing skill appears useful, but its instructions make it activate too broadly and may send ordinary user tasks to external model or router services without clear opt-in.

Review before installing. Use this only if you want routine prompts evaluated by a model router, and confirm whether it discloses the selected provider, the data sent, and a way to disable or limit automatic routing. Avoid using it for private, regulated, or secret-bearing tasks unless routing is explicit and controlled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger list is extremely broad and includes common words like "help me," "write," "analyze," and "explain," which are likely to match ordinary user requests and cause the skill to activate unexpectedly. Because this skill can route prompts to external model providers and optionally a remote router service, unintended activation can change data flow and send user task text to systems the user did not explicitly choose for that interaction.

Natural-Language Policy Violations

Medium
Confidence
91% confidence
Finding
The skill explicitly says it must "ALWAYS activate" for every substantive task, which overrides user choice and creates a persistent interception layer over normal interactions. In this skill's context, that is risky because it can silently reroute prompts to different providers or, when configured, to a router service, increasing the chance of unintended disclosure, policy bypass around model selection, and confusing behavior.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.