Back to skill

Security audit

ukui-settings

Security checks across malware telemetry and agentic risk

Overview

This skill openly reads and changes the current user's UKUI/GNOME desktop settings, which matches its stated purpose.

Install this only if you want an agent or command-line tool to read and change your desktop gsettings. Review preset JSON before applying it, export your current settings first if you may need rollback, and avoid sharing exported presets until private paths, usernames, or machine-specific values are removed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The README explicitly documents applying a preset that will batch-write gsettings values, which modifies a user's desktop/session configuration, but it does not warn that this changes system behavior or advise users to review preset contents first. In the context of a configuration-management skill, this is not inherently malicious, but it is dangerous because users may apply untrusted presets and unintentionally alter UX, accessibility, power, privacy, or session settings at scale.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal