Back to skill

Security audit

IMA知识库上传

Security checks across malware telemetry and agentic risk

Overview

This is an instruction-only upload helper whose credential use and external document upload are aligned with its stated IMA knowledge-base purpose, but users should handle secrets and destinations carefully.

Before installing or using this skill, review the separate ima-skill helper it depends on, use least-privilege IMA/COS credentials, avoid pasting secrets into command lines when safer options are available, and verify both the file contents and KB_ID so sensitive documents are not uploaded to the wrong knowledge base.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill instructs operators to pass secret-bearing COS credentials and temporary tokens directly on a command line, which commonly exposes them through shell history, process listings, logs, and screenshots. Because the skill provides no warning or safer handling guidance, users may inadvertently leak credentials that can be reused to access or upload content to the backing storage.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill is explicitly designed to upload local Markdown and other files to external IMA/COS services, but it does not provide a user-facing notice that document contents will leave the local environment. In a knowledge-upload workflow, this omission increases the risk of accidental exfiltration of sensitive reports, regulated data, or internal documents by users who may assume the action is purely local automation.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.