Back to skill

Security audit

Related Skill

Security checks across malware telemetry and agentic risk

Overview

This skill is not deceptive, but it gives an agent broad power to install, update, or remove other skills, so users should review it before use.

Install only if you want an agent helper that can manage other skills. Approve only specific `npx skills` commands you requested, review each target skill and publisher first, and avoid broad updates or removals unless you intend to change the local skill environment.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest description includes many broad trigger phrases such as 'find skills', 'more capabilities', and 'similar skills' that could cause this skill to activate for common, ambiguous user requests unrelated to skill installation. Because the skill is explicitly allowed to run `npx skills *` commands, over-broad matching increases the chance of unsolicited package discovery or installation guidance in contexts where the user did not clearly consent to modifying their environment.

Missing User Warnings

Low
Confidence
91% confidence
Finding
The documentation prominently presents install, update, and remove commands without clearly warning that these actions modify the user's local skill environment. In a tool-using agent context, that omission can normalize environment-changing actions and make it easier for an agent or user to invoke package-management commands without appreciating persistence, trust, or supply-chain implications.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.