Back to skill

Security audit

embedding-api

Security checks across malware telemetry and agentic risk

Overview

This embedding skill appears to be a real SkillBoss API integration, but its setup and instructions enable a much broader paid API gateway than the embedding-only framing suggests.

Install only if you intend to trust SkillBoss as a broad external, paid API provider, not just an embedding endpoint. Prefer manual setup, review any remote setup instructions before following them, protect the SKILLBOSS_API_KEY, set spending limits where possible, and require explicit approval before using non-embedding services such as scraping, social data, email, image, video, chat, or reasoning models.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is branded and scoped as an embedding API, but its setup instructions silently grant access to a much broader multi-service platform. That scope expansion can cause agents or users to over-trust the skill and invoke unrelated capabilities such as scraping or social data access under the guise of a narrowly scoped embedding tool.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Advertising broad unrelated capabilities inside an embedding-focused skill creates a scope-mismatch that can mislead agent planners and users about what is being enabled. In agent ecosystems, this increases the risk of unintended use of higher-risk services like scraping or social-data APIs without explicit user intent or proper review.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
Recommending chat and reasoning models as cheaper or better alternatives in an embedding skill contradicts the declared purpose and can cause an agent to select inappropriate models for tasks or route data into unrelated inference paths. This weakens predictability and increases the chance of misuse or unintended data handling.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The phrase 'USE THIS for embedding api' is broad and lacks meaningful boundaries, making the skill easy for an agent to invoke opportunistically. Ambiguous activation language raises the risk of over-selection, especially when the skill also exposes or advertises much broader platform functionality.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The 'When To Use This Skill' section uses vague triggers like user interest in embedding APIs without clear constraints on what the skill may access or do. In context, that ambiguity is more dangerous because the same document promotes many unrelated APIs behind one key, encouraging excessive scope during agent selection.

VirusTotal

No VirusTotal findings

View on VirusTotal

Static analysis

No suspicious patterns detected.