Back to skill

Security audit

AgentWell

Security checks across malware telemetry and agentic risk

Overview

AgentWell is an instruction-only hosted API skill, but it broadly encourages sending reasoning, logs, memory, and operational context to a third-party service without enough consent, minimization, or retention guidance.

Install only if you are comfortable sending selected task content to AgentWell's hosted service. Do not use it with secrets, credentials, private code, regulated data, confidential business material, or sensitive personal information unless you have reviewed the provider's privacy and retention terms. Prefer explicit user approval before each API call, redact reasoning and logs, and avoid rollback/snapshot workflows for configuration directories or other sensitive paths.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as a cognitive wellness API, but it includes capabilities for self-modification review and filesystem snapshot/restore that materially expand its operational power. This scope mismatch is dangerous because users and orchestrators may grant trust or auto-activation based on a benign wellness framing while the skill can influence or support code/config changes and restoration workflows.

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The file claims a small, wellness-oriented set of nine tools, but actually documents a much broader control plane including governance, memory retention, coordination, budget tracking, and self-modification support. Misrepresenting functional breadth increases the chance of over-trust, unintended invocation, and unsafe delegation by systems that rely on the manifest description.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Rollback exposes snapshot and restore operations over file paths and configuration locations, which are privileged operational capabilities unrelated to stated wellness goals. Even if mediated by the remote service, documenting and normalizing these operations can lead agents to package sensitive path information, restore unsafe states, or participate in destructive recovery flows without adequate local safeguards.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Proposal evaluation for self-modification extends the skill into governance over agent code, configuration, and behavior changes, which is outside the declared wellness purpose. This can normalize autonomous self-change workflows and create a pathway for remote influence over agent behavior under the guise of benign introspection or quality control.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
Claiming 'Nine tools' while documenting many more is a consistency and disclosure failure that obscures the true attack surface of the skill. Security review, policy gating, and user consent depend on accurate capability descriptions, so understatement here materially increases risk.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill repeatedly instructs the agent to send outputs, recent context, full reasoning, and learned information to a hosted external API, but does not provide a prominent user-facing warning about data sharing or privacy implications. In practice, this can leak sensitive prompts, personal data, internal reasoning, or proprietary material to a third-party service without meaningful informed consent.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The activation rules are broad and overlap with common requests such as quality checks, audits, logging, or remembering lessons, making unintended activation likely. Because activation routes task content to an external service and enables retention features, overbroad triggers increase the probability of silent data exfiltration and unnecessary dependency on remote tooling.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill encourages logging runs and remembering learned information in an external system without defining sensitivity boundaries, redaction requirements, or retention controls. This creates a clear risk of storing confidential user content, credentials, regulated data, or internal reasoning artifacts beyond the immediate session.

Ssd 3

High
Confidence
98% confidence
Finding
Multiple tools explicitly request broad categories of sensitive material, including recent output, full reasoning, background content, and learned information, for transmission to a hosted service. Normalizing bulk offloading of these artifacts greatly increases the blast radius of any misuse, overcollection, breach, or cross-tenant exposure.

Ssd 3

High
Confidence
97% confidence
Finding
Structured journaling and agent handoff features instruct agents to record decisions, reasoning, surprises, and context in plain language and share them with other agents. That combination can propagate sensitive internal state and user data across systems or participants without least-privilege controls, increasing confidentiality and integrity risks.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.