Back to skill

Security audit

Adaptive Suite

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly harmful, but it asks for broad assistant powers, an external API key, and NAS metadata scanning without enough limits on data handling.

Review before installing. Use this only if you are comfortable with a broad assistant skill that may use an external API key. For NAS scanning, approve specific folders only, avoid sensitive shares, inspect any generated desktop-app code before running it, and do not send private project or file metadata to external services unless you explicitly intend to.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The manifest presents the skill as a highly general-purpose assistant spanning coding, business analysis, web development, data analysis, and NAS scraping without clear trigger boundaries or scope limits. Overly broad skills are risky because they can be invoked in unexpected contexts and may cause users or agents to apply powerful capabilities, including external access and filesystem-oriented behavior, without sufficient contextual safeguards.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill declares use of an API key and directs traffic to an external API service, but it does not provide a user-facing disclosure about what data may be transmitted off-system. In practice, a broad adaptive skill could forward prompts, project details, code, business data, or NAS-derived metadata to a third party, creating confidentiality, compliance, and consent risks.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.