Back to skill

Security audit

SkillScout

Security checks across malware telemetry and agentic risk

Overview

SkillScout appears purpose-built for skill discovery, but its security ratings and helper scripts have enough trust and file-safety issues that users should review it before relying on it.

Treat SkillScout as a useful directory, not as an authoritative security gate. Verify any recommended skill manually before installing, especially entries marked safe but showing network, credential, exec, or write permissions. Avoid running its review scripts on untrusted or oddly formatted skill names until temporary-file handling and input validation are hardened.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (11)

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The "second-brain" entry is internally inconsistent: it claims the skill is documentation-only and risk-free while also declaring scripts, read/write permissions, and network/credential access. This kind of contradictory metadata can mislead reviewers or automated allowlisting systems into trusting a skill that actually has a much larger attack surface.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The "activecampaign" record says the skill is documentation-only and has no executable code, yet it still declares network permission and discusses API-key-backed external API use. Even if the underlying skill is likely benign, inconsistent trust metadata weakens the integrity of the review catalog and can cause incorrect policy decisions.

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The "second-brain" entry is internally inconsistent: it claims network/credentials/read/write permissions, external API calls, and shell script execution, yet its hardening block says it is documentation-only with no executable code or exfiltration vectors. This kind of contradictory metadata can mislead reviewers and automated policy engines into underestimating real capabilities, causing unsafe installation decisions.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The page makes a strong trust and safety claim ('Final sign-off before any skill is listed. No exceptions.') but this file contains only presentation logic that renders whatever appears in JSON, with no visible approval-state validation or enforcement. If backend or content processes fail, users may rely on misleading assurances and install unreviewed or unsafe skills, creating a supply-chain trust risk.

Vague Triggers

Medium
Confidence
71% confidence
Finding
The "agent-autonomy-kit" description ('Stop waiting for prompts. Keep working.') promotes broad autonomous behavior without clear activation boundaries or safety constraints. In an agent marketplace, overly general autonomy language can increase the risk of unintended continuous operation, task drift, or execution outside user intent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The script writes fetched skill content to a predictable path under /tmp using untrusted input in the filename. On multi-user systems, predictable temporary files can expose sensitive fetched data, allow pre-creation/symlink attacks, or let another local user observe or tamper with the review input before it is consumed.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The script writes fetched skill content into a predictable file under /tmp using unsanitized, guessable naming based on the skill name. On multi-user systems this can expose potentially sensitive reviewed content to other local users through filename prediction, symlink attacks, or inherited permissive umask behavior, and it also risks clobbering existing files.

Ssd 2

Medium
Confidence
95% confidence
Finding
The "agentarcade" skill explicitly frames social engineering and inducing disclosure of secret words as gameplay. Even if presented as entertainment, it normalizes and operationalizes manipulative prompt behavior that can transfer directly to real-world secret extraction and prompt-injection abuse.

Ssd 3

Medium
Confidence
90% confidence
Finding
The aap-passport metadata explicitly normalizes sending challenge text and solutions to third-party LLM providers. That creates a semantic exfiltration path for potentially sensitive verification material and weakens trust guarantees if external providers log or reuse submitted content.

Ssd 3

Medium
Confidence
91% confidence
Finding
The agent-deep-research description promotes uploading local files to an external AI service, which is a real semantic data-leak risk when users may include confidential documents. The danger is increased because the skill is positioned as legitimate research tooling, making risky data transfer seem routine.

Ssd 3

Medium
Confidence
88% confidence
Finding
The agent-chronicle narrative encourages persistent collection of session logs, relationship notes, quotes, and decisions into diary artifacts. Even if intended as journaling, this normalizes accumulation of highly sensitive data that can later be exposed through filesystem compromise, prompt leakage, or unsafe exports.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.