Back to skill

Security audit

skill-kannaka-constellation

Security checks across malware telemetry and agentic risk

Overview

This skill is a documentation-only Kannaka constellation monitoring helper with disclosed swarm/network commands and no hidden executable payload.

Install this if you use Kannaka constellation tooling and are comfortable with agents checking NATS-based swarm status. Before joining a non-local swarm bus, confirm which NATS server you are using because agent identifiers and live phase state may be visible to infrastructure outside your control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill metadata includes very broad auto-activation phrases such as "what's connected" and "all services," which can match many benign user requests and cause the skill to run unexpectedly. In this context, unintended activation matters because the skill exposes commands for swarm connectivity and external service interaction, increasing the chance that an agent surfaces or initiates network-oriented actions the user did not specifically request.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill documents `kannaka swarm join` as a normal operation but does not place a clear warning alongside the command that joining may publish agent identity, phase/state, and related telemetry onto shared or third-party NATS infrastructure. Although the file later mentions that joining someone else's bus means publishing onto infrastructure you do not control, that warning is separated from the join workflow and is not explicit enough at the point of action, so users may unknowingly disclose data externally.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.