Back to skill

Security audit

ISO 评审助手/ISO Audit Assistant

Security checks across malware telemetry and agentic risk

Overview

This ISO audit assistant performs disclosed, user-directed document analysis and generation without evidence of hidden persistence, exfiltration, or destructive behavior.

Install only if you intend to use it on ISO audit and management-system documentation. Treat uploaded or referenced company documents as sensitive: redact unnecessary personal, legal, security, or commercial details, and point directory analysis only at folders meant for audit review. If using the publisher instructions, handle API tokens as secrets and avoid pasting them into shared terminals, screenshots, logs, or shell history.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding
The skill instructs the agent to read, parse, transform, and generate files via local scripts, but no permissions are declared. That mismatch can cause reviewers or the runtime to underestimate the skill's access needs, increasing the risk of unintended file access to sensitive company documents used for ISO audits.

Missing User Warnings

Medium
Confidence
86% confidence
Finding
The publishing instructions tell users to paste a full API token into a shell command and note it is shown only once, but they do not explicitly warn users to keep the token secret, avoid sharing it in screenshots/logs, or prefer safer input methods. This can lead to accidental credential exposure through shell history, screen recording, copied commands, or collaborative terminal sessions, enabling unauthorized publishing or account actions.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The activation criteria are very broad and trigger on many common ISO-, compliance-, and audit-related mentions. This can cause the skill to activate in contexts where the user did not intend document parsing or generation, increasing the chance of unnecessary handling of sensitive business materials or inappropriate workflow steering.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly supports parsing, analyzing, and converting internal company documents, which commonly contain confidential operational, HR, legal, safety, and security information. Without any privacy, retention, or handling warning, users may disclose sensitive documents without informed consent, creating material confidentiality and compliance risk.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.