Back to skill

Security audit

Find Skills — Search Every Skill Registry at Once

Security checks across malware telemetry and agentic risk

Overview

This skill coherently searches public skill registries and gives review guidance, with no evidence of hidden installation, exfiltration, persistence, or destructive behavior.

Before installing a recommended skill, review that candidate's SKILL.md and bundled scripts yourself. Treat GitHub-only results as unscanned by this tool even if they appear in the same report, and only approve npx skills installation commands for a specific skill you have chosen.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill description promises security-scanning of top candidates across major registries, but only skills.sh and clawhub arrays are passed through scan_board; GitHub results are displayed without equivalent scanning. In a tool explicitly positioned as helping users choose 'SAFE' skills, this creates a trust gap that can cause users to rely on unvetted GitHub recommendations and install a malicious skill under a false sense of review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.