Back to skill

Security audit

Phoenix Shield

Security checks across malware telemetry and agentic risk

Overview

Phoenix Shield presents itself as a production backup and rollback tool, but the submitted package lacks the runtime program needed to verify those safeguards while encouraging privileged system changes.

Review carefully before installing. Do not use this on production systems, enable the cron example, run deploy or rollback commands, or grant administrative privileges until the missing executable is supplied and reviewed, exact commands and targets are approved, backups are verified, and rollback behavior is tested in a disposable or staging environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Lp3

Medium
Category
MCP Least Privilege
Confidence
86% confidence
Finding
The skill presents numerous shell commands and operational workflows but does not declare corresponding permissions, which weakens transparency and informed consent for users and orchestration systems. In a skill meant for production updates and rollback, undisclosed shell capability increases the chance of unexpected command execution against sensitive systems.

Vague Triggers

Medium
Confidence
74% confidence
Finding
The activation language is very broad, covering routine updates, production deployments, and high-availability operations, which could cause the skill to be invoked in many sensitive contexts. Because the documented actions include package upgrades, deploy hooks, rollback, and remote targeting, overbroad triggering raises the risk of accidental use on critical infrastructure.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The documentation describes automatic rollback through config revert, package downgrade, full restore, and emergency mode without clearly warning that these actions can revert system state and disrupt live services. In production environments, an automatically triggered restore or downgrade can cause data loss, configuration regression, or service instability if performed without explicit operator approval and safeguards.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The examples execute privileged, system-wide operations such as apt upgrade, service checks, and root-owned hooks without an explicit warning about trust boundaries or disruption risk. Copy-paste use of these examples could run arbitrary scripts as root, alter packages across a host, and impact availability on production systems.

VirusTotal

59/59 vendors flagged this skill as clean.

View on VirusTotal