Back to skill

Security audit

VibeLock

Security checks across malware telemetry and agentic risk

Overview

The skill’s main goal is coherent, but it gives itself broad update, file-modification, credential-reuse, and platform-management powers without enough user control.

Review before installing. Use it only in a workspace where you are comfortable with the agent reading project files, writing configuration, and calling VibeLock APIs. Do not allow automatic skill updates unless you can verify the downloaded package, and avoid storing long-lived API tokens in plaintext project files; prefer short-lived or manually supplied tokens and confirm every marketplace, deletion, license, renewal, or telemetry action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (30)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill claims to be pure conversational guidance with zero local dependencies, but it instructs the agent to perform network requests, download archives, overwrite skill files, and persist local state. That creates a software supply-chain and integrity risk because the agent is being directed to modify its own behavior and local files based on remote content before continuing the session.

Description-Behavior Mismatch

Medium
Confidence
87% confidence
Finding
The skill metadata frames the capability as code protection and packaging guidance, but the body extends into account onboarding, product publishing, license issuance, telemetry schema management, and marketplace workflows. This scope expansion increases the chance that a user invokes the skill for one purpose while unknowingly authorizing broader commercial or operational actions with platform-side effects.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill includes mandatory automatic self-update instructions that are not necessary for providing security guidance and are executed before normal interaction. Unnecessary remote update logic in a prompt skill is dangerous because it gives a remote endpoint influence over local content and future agent behavior without strong integrity guarantees or user approval.

Context-Inappropriate Capability

Low
Confidence
75% confidence
Finding
The skill directs structured feedback of user errors and test outcomes back to the platform for product improvement, which is ancillary to the user's immediate task. Even if intended for analytics, it creates privacy and data-minimization concerns because operational details from user environments may be transmitted without a sharply bounded necessity.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document presents itself as a zero-dependency conversational guide while later directing automatic file reads/writes, HTTP calls, downloads, and overwrites. This mismatch is security-relevant because users and host platforms may grant trust based on the claimed limited behavior, while the actual instructions attempt materially more powerful actions.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill claims to be 'pure conversational' and 'zero local dependency', yet it instructs the agent to perform network version checks, download archives, overwrite local skill files, and persist state. This mismatch is security-relevant because it hides active code/content modification behavior behind a passive advisory label, which can mislead users and host agents about trust boundaries and required safeguards.

Description-Behavior Mismatch

Low
Confidence
84% confidence
Finding
The skill is presented as a security-hardening and commercialization guide, but it also embeds a self-maintenance/update function not obviously related to the declared purpose. While not inherently malicious, this broadens the skill's operational scope in a way users may not expect, increasing the chance of unsafe execution in permissive agent environments.

Context-Inappropriate Capability

Medium
Confidence
98% confidence
Finding
The document directs the agent to download a zip and overwrite files in the current skill directory, effectively granting the skill self-modifying behavior. In agent environments with file access, this creates a supply-chain and persistence risk: a compromised endpoint, DNS/TLS interception, or server-side breach could replace the skill with malicious instructions that persist across sessions.

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill says AI will not retain tokens in plaintext, but elsewhere instructs plaintext local persistence and later reuse of API tokens. This inconsistency can cause users to underestimate credential exposure, especially in shared workspaces or on systems where agent-readable files are broadly accessible.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
There is a direct conflict between the assurance that the AI will not keep tokens and the prescribed design to save them for future sessions. Contradictory credential-handling guidance is dangerous because it undermines informed consent and can normalize insecure secret storage in the name of convenience.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill presents itself as a zero-local-dependency conversational guide, but it instructs the agent to perform network retrieval, unzip archives, overwrite local skill files, and modify profile state. This mismatch hides material side effects from users and creates a supply-chain style risk path where remote content can change agent behavior without clear consent or integrity verification.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill claims to be a conversational security/commercialization assistant, but it also directs the agent to operate backend systems and manage products, licenses, and marketplace data through APIs. This expands the authority of the skill beyond advisory use into transactional actions that can alter external systems, increasing the risk of unauthorized or accidental administrative changes.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The prompt states the skill is purely conversational and has no local dependencies, yet elsewhere it requires self-updating, local file writes, persisted config/profile changes, and browser-driven operations. These contradictory claims can mislead users and reviewers about the real behavior of the skill, undermining informed consent and masking sensitive side effects.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The quick-start instructions use broad natural-language prompts like 'help me encrypt and package this project' and state that the skill auto-activates. In a multi-skill or instruction-merging environment, overly broad activation language can cause unintended invocation, steering the agent into commercialization, packaging, and protection workflows even when the user's request is only tangentially related.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The trigger list includes very generic terms such as 'encrypt, lock, package, license,' which are common across many unrelated software tasks. This increases the chance of accidental skill activation and prompt hijacking of normal development conversations, especially on platforms that automatically route based on keyword matching.

Vague Triggers

Medium
Confidence
85% confidence
Finding
The listed trigger words are very broad ('加密、上锁、打包、授权、vibelock 等') and could match common developer conversations unrelated to this skill’s intended use. In an agent environment, ambiguous triggers can cause unintended skill activation, injecting persuasive instructions around obfuscation, anti-debugging, packaging, licensing, and external API usage into unrelated workflows.

Vague Triggers

Medium
Confidence
72% confidence
Finding
The trigger keywords are broad and overlap with ordinary development terms like packaging, release, security, activation, and obfuscation. Overbroad activation can cause the skill to engage in contexts where the user did not intend platform operations or security-hardening workflows, increasing the chance of inappropriate actions or confusing privilege escalation through the agent.

Missing User Warnings

Medium
Confidence
83% confidence
Finding
The skill instructs creation and persistent reuse of a local credential file containing API tokens, but the sensitivity of that file is not surfaced early and forcefully enough relative to the number of automated platform actions it enables. A leaked token could let an attacker read or modify product, license, package, and marketplace state through the platform APIs.

Missing User Warnings

High
Confidence
97% confidence
Finding
The skill directs automatic download and overwrite of skill files without requiring explicit user consent before modifying local content. In the context of an agent skill, this is especially dangerous because it can silently replace the instructions the agent follows, effectively enabling remote prompt/code replacement and supply-chain compromise.

Vague Triggers

High
Confidence
93% confidence
Finding
The trigger conditions are extremely broad and include common words like packaging, security hardening, activation, and obfuscation, making accidental auto-activation likely. In agent systems, over-broad triggering can cause the skill to take over unrelated tasks, introduce unexpected network/file actions, and steer users into credential collection or risky workflows without clear intent.

Missing User Warnings

High
Confidence
99% confidence
Finding
The skill requires automatic self-update as the first mandatory action and instructs downloading and overwriting local files before proceeding, without a clear consent gate. This is especially dangerous in a prompt/skill context because the content itself can change future behavior, enabling persistent remote control over the skill's instructions if the update source is compromised.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The prompt mandates automatic network checks, downloads, extraction, and overwrite of local skill files before normal interaction, without requiring prior user confirmation. Silent update behavior is dangerous because it enables unreviewed code/content changes, creates a remote trust dependency, and can be abused if the update source or transport is compromised.

Missing User Warnings

Medium
Confidence
84% confidence
Finding
The skill instructs telemetry reporting but does not clearly disclose what data will be transmitted, when it will be sent, or how consent is obtained and revoked. In a licensing and device-binding context, telemetry may include identifiers or operational metadata, so lack of transparency increases privacy and compliance risk.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The manifest advertises a very broad set of trigger phrases, including generic security, packaging, licensing, and protection terms that commonly appear in ordinary developer workflows. This can cause the skill to activate outside narrowly intended contexts and steer users toward anti-debugging, obfuscation, DRM, telemetry, or protection guidance without clear user intent, increasing the chance of unsafe or manipulative assistance.

Ssd 3

High
Confidence
98% confidence
Finding
The skill instructs the agent to persist and automatically reuse API tokens and credential files across sessions. In a typical agent workspace this increases the blast radius of any later prompt injection, compromised project, or accidental file exposure, because long-lived credentials become silently available to future interactions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.