Back to skill

Security audit

DNSFilter

Security checks across malware telemetry and agentic risk

Overview

This appears to be a disclosed DNSFilter integration, with the main caution that its trigger wording is broader than ideal.

Install this only if you want the agent to use your connected DNSFilter account. Ask it to use the skill only for explicit DNSFilter tenant operations, and review any proposed policy or configuration changes before allowing them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger text is overly broad because it instructs the agent to use this skill for any DNSFilter-related request, without clearly limiting usage to tasks that actually require the connected connector. This can cause unnecessary tool invocation, expand the scope of data exposure from the user's DNSFilter account, and crowd out safer alternatives such as answering general informational questions without accessing tenant data.

VirusTotal

61/61 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.