Back to skill

Security audit

Jack

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed CAD-generation workflow that sends user-entered design parameters to an external service and creates guest-access job links, with no evidence of hidden code or destructive behavior.

Install only if you are comfortable sending the project details you enter to the external CAD service and receiving guest-access links or codes for generated production sheets. Avoid entering confidential designs unless the service's sharing and retention model is acceptable, and confirm the skill is being invoked for the intended CAD task before proceeding.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases include extremely generic terms such as "jack" and common natural-language requests, which can cause this skill to activate for unrelated conversations. Misrouting a user into a workflow that collects parameters and sends them to an external service increases the chance of unintended data disclosure or unwanted external actions.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill creates a guest-access production sheet and immediately exposes a shareable URL/code without warning the user that the link may grant access to generated files and workflow status. Because the flow is explicitly unauthenticated, accidental disclosure of the URL or guest code could allow unauthorized parties to view or access the user's production artifacts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.