Back to skill

Security audit

ZeroToken

Security checks across malware telemetry and agentic risk

Overview

The skill is not malicious, but it mixes token-saving guidance with broad local file changes and browser/web search behavior that users should review before installing.

Install only if you are comfortable giving the skill local file-editing authority and allowing its research guidance to use browser/web search tools. For encoding repair, run scan or preview first and use --backup before convert or fix operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding
The skill is presented primarily as a token-efficiency discipline, but it also embeds substantial file-modification, encoding-repair, reporting, and repository-operation workflows. That mismatch can cause operators to enable or trust the skill under a narrower risk assumption than its actual behavior, increasing the chance of unintended file changes or broader local impact.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
The skill introduces browser/MCP/web-search guidance unrelated to its core stated purpose of concise, token-efficient task execution. Expanding a skill's behavior into external search increases data exposure and network reach, and users may invoke it without realizing it can drive browser-based retrieval or search workflows.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The manifest description omits that the skill documents use of Chrome MCP and web_fetch for external search. Undisclosed network/browser behavior is dangerous because users and policy systems may classify the skill as local-only efficiency guidance when it can actually transmit queries to outside services and retrieve untrusted web content.

Description-Behavior Mismatch

Low
Confidence
87% confidence
Finding
The workflow recommends git configuration and commit-related actions, but this behavior is not cleanly represented in the manifest/security capability disclosures. Even when limited to local repository settings, undisclosed VCS operations can alter audit trails, repository state, or user expectations about what the skill is allowed to change.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The convert mode rewrites files in place regardless of whether --backup is supplied, so a user can irreversibly alter or damage content if decoding guesses are wrong or replacement characters are introduced. In the context of an encoding-conversion utility, this is not malicious, but it is a real safety weakness because the tool operates recursively over many files and can cause broad accidental data loss.

VirusTotal

VirusTotal engine telemetry is currently stale for this artifact.

View on VirusTotal

Static analysis

No suspicious patterns detected.