Back to skill

Security audit

Prompt Benchmark

Security checks across malware telemetry and agentic risk

Overview

This skill performs local static prompt evaluation with a small lint script and no evidence of hidden data access, persistence, or destructive behavior.

Installers should understand that this skill may read prompt files they explicitly ask it to analyze and may run its bundled Python lint script, but the inspected artifacts do not show hidden network calls, credential handling, persistence, or destructive actions.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding
Without declared permissions the skill's intent is opaque and cannot be validated.

Natural-Language Policy Violations

Low
Confidence
92% confidence
Finding
The short description is written only in Chinese ("静态诊断 Prompt 质量、结构、安全性与模型兼容性") while the rest of the manifest is in English, and the file does not indicate that this skill is intended only for Chinese-speaking users or a China-specific context. This creates a natural-language locale constraint without user opt-in or justification, which matches the language/locale policy violation criterion.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.