Back to skill

Security audit

Geoskill: DEM Terrain Analysis

Security checks across malware telemetry and agentic risk

Overview

This is a local DEM terrain-analysis skill with no credential, network, persistence, or privileged behavior, though its documentation appears incomplete or inconsistent.

Before installing, treat this as low security risk but verify functionality: the referenced Python tool is not included in the inspected artifact, and the watershed/viewshed documentation may be incomplete. Use it only on DEM files you intend to process and review generated output paths before running batch commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
84% confidence
Finding
The feature table lists "Watershed" as a supported analysis output, implying the tool can generate watershed products. However, the usage examples enumerate available commands and include hydrology commands only for flow direction and flow accumulation, with no watershed command shown anywhere in the documentation, indicating a likely mismatch between claimed capability and actual exposed behavior.

Description-Behavior Mismatch

Medium
Confidence
86% confidence
Finding
The feature list advertises "Viewshed" output, and parameters for viewshed are documented later, but the usage section does not include any viewshed command example and no command is shown among the listed invocations. This creates a documentation-to-behavior mismatch suggesting the skill claims a capability that is not actually available or not properly wired into the CLI.

Natural-Language Policy Violations

Low
Confidence
82% confidence
Finding
The file includes a dedicated Chinese-language section and bilingual manifest text, but does not indicate that language selection is optional or user-driven. Under the policy rule, forcing a specific language or locale without opt-in can be a natural-language policy concern.

Scope Creep

Low
Category
Excessive Agency
Content
the Software, and to permit persons to whom the Software is furnished to do so.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS
FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR
COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER
IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN
Confidence
70% confidence
Finding
NOT LIMITED TO

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.