Back to skill

Security audit

AI Capability Analyzer

Security checks across malware telemetry and agentic risk

Overview

This skill is not destructive, but it overstates its live search and safety-review abilities while recommending other skills as safe.

Treat this as a rough, offline recommendation helper only. Do not rely on its safety ratings as a real security review, and independently inspect any skill it recommends before installing. Avoid providing API keys unless a future version clearly documents and implements live API use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims that all user queries are processed locally unless cloud APIs are explicitly enabled, but elsewhere it declares OPENAI_API_KEY as a required dependency and states that LLM-based understanding is part of the core design. This creates a misleading privacy guarantee that may cause users to submit sensitive data under false assumptions, leading to unintentional disclosure to external services.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The code comments and function name imply a real-time ClawHub API lookup, but the implementation only returns hardcoded mock data when an API key is present. This can mislead users into believing recommendations are current and externally validated, which is dangerous in a tool that markets itself as performing real-time skill search and safety assessment.

Intent-Code Divergence

High
Confidence
99% confidence
Finding
The tool outputs fixed claims such as '满足100/3规则', '安全评级: 高', and five-star safety without implementing any substantive security evaluation beyond a basic download-count threshold. In security-sensitive recommendation workflows, this creates false assurance and may cause users to install unvetted or risky skills based on fabricated safety signals.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill description advertises intelligent analysis, real-time skill search, and security assessment, but the implementation mainly performs keyword matching against a static local object and simplistic heuristics. This mismatch is especially risky because users may rely on the claimed security analysis capability to make trust decisions about third-party skills.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The trigger phrases are broad and overlap with ordinary user requests about recommendations, comparisons, or safety checks. Overbroad activation can cause the skill to run unexpectedly, potentially sending user prompts or context to external APIs and influencing agent behavior when the user did not intend to invoke this capability.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.