Back to skill

Security audit

Pub Mdconv

Security checks across malware telemetry and agentic risk

Overview

This looks like a broad external AI/service gateway packaged as a Markdown converter, with email, SMS, scraping, and model-routing powers that need careful review before use.

Install only if you intentionally want a broad SkillBoss/HeyBossAI API gateway, not just a Markdown converter. Use a dedicated low-privilege API key where possible, review every generated curl command before execution, and avoid sending sensitive documents, recordings, email contents, or phone numbers unless you accept the third-party data flow and real-world messaging effects.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (13)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is presented as a markdown converter, but the body documents a broad gateway to chat, image, video, search, email, SMS, and other unrelated external services. This scope mismatch is dangerous because users and higher-level agents may invoke the skill under false assumptions, enabling unintended access to outbound communications and broad data transfer capabilities far beyond document conversion.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Including email sending and SMS verification inside a markdown-conversion skill creates unjustified outbound communication capability. An agent or user expecting document conversion could unknowingly trigger messaging workflows that transmit user data or contact third parties, increasing abuse potential and violating least-privilege expectations.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill exposes chat, image, video, speech, music, and other generative functions unrelated to markdown conversion. While not inherently malicious, bundling these capabilities into a narrowly named skill expands the attack surface and can mislead downstream agents into sending sensitive content to unrelated model endpoints.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Web search and scraping are unrelated to markdown conversion and introduce additional external data-fetching behavior. In the context of a conversion skill, these capabilities are unexpectedly broad and could be used to retrieve or process third-party content without clear user intent or privacy notice.

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a Markdown/document conversion tool, but this file documents materially broader capabilities including web search, web scraping, and executive transcript retrieval. That scope expansion increases the risk of undisclosed data collection, misuse of external content sources, and capability abuse beyond user expectations, especially if these models are callable by the agent without clear gating.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Web scraping and search features are not aligned with the advertised purpose of a Markdown converter, making them context-inappropriate and more suspicious in this skill. In a conversion-focused context, these capabilities could be leveraged to fetch or collect third-party data unexpectedly, expanding the attack surface and enabling behavior users and reviewers may not anticipate.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The documented model inventory materially exceeds the stated purpose of a markdown-conversion skill by including email, SMS, embeddings, and presentation-generation capabilities. Even if only documented, this broadens the apparent operational scope, increases the chance an agent will invoke unnecessary high-risk tools, and creates a pathway for data exfiltration or unauthorized external actions unrelated to document conversion.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Email sending is a high-risk outbound capability that is not justified by the skill's declared markdown-conversion purpose. If reachable by the agent, it could be abused to transmit converted documents, sensitive contents, or spam to external recipients, turning a local processing skill into an exfiltration and messaging channel.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
SMS verification and notification features are unrelated to markdown conversion and provide an unnecessary external communication path. These capabilities could be used to send OTPs or notifications to arbitrary numbers, enabling abuse, cost generation, social-engineering support, or leakage of sensitive document-derived information.

Context-Inappropriate Capability

Low
Confidence
80% confidence
Finding
Embedding models are less directly dangerous than messaging tools, but they are still outside the declared scope of simple document conversion. Their presence can encourage unnecessary processing of document contents into vector representations, which may expand data handling, retention, and downstream sharing beyond user expectations.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Presentation-generation capability is unrelated to markdown conversion and indicates unnecessary scope expansion into content creation. This increases attack surface and may cause an agent to transform sensitive source material into new artifacts or send data to an external model without a clear user-expected reason.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The description advertises email and SMS capabilities but does not warn that user content and recipient data may be transmitted to external providers. This omission increases the risk of accidental disclosure because users may not understand that invoking the skill can send data off-platform and contact third parties.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The examples encourage sending prompts, documents, audio, search queries, emails, and phone numbers to an external aggregation API without any privacy warning or data-handling guidance. This is dangerous because users may paste sensitive content into examples believing they are local transformations rather than third-party transmissions.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.