Back to skill

Security audit

Axioma Skill Evaluator Strict EN

Security checks across malware telemetry and agentic risk

Overview

This skill is a local skill evaluator, but it does not enforce the strict 90% approval rule it advertises.

Review before installing. Treat it as a heuristic local evaluator, not a trustworthy strict 90% approval gate, unless the threshold logic is fixed. Run it only on explicit test skill directories, avoid --all unless you understand the hard-coded paths, and check where reports will be written.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The implementation contradicts the skill's advertised security/quality gate by approving skills at 70% instead of enforcing the stated strict 90% minimum. In a pipeline that relies on this evaluator as a trust boundary for skill admission, this can allow lower-quality or unsafe skills to be incorrectly approved and propagated downstream.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The report and CLI messaging explicitly tell operators that approval is granted at 70% and failure only occurs below 50%, reinforcing the incorrect policy and creating misleading audit artifacts. This increases the chance that humans will trust and ship skills that should have been rejected under the advertised strict 90% gate.

Vague Triggers

Medium
Confidence
85% confidence
Finding
Broad trigger phrases such as generic evaluation or approval language can cause the skill to activate on ordinary user requests unrelated to this specific strict evaluator. In context, that is more dangerous because the skill includes commands with shell, file, and network implications, so accidental invocation could lead to unintended analysis, scanning, or report generation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.