Back to skill

Security audit

Find Agent

Security checks across malware telemetry and agentic risk

Overview

This directory skill is mostly coherent, but it asks for broad local profiling and can contact third-party agents in ways users may not fully expect.

Install only if you are comfortable with OceanBus network lookups and public directory publishing. Before using it, avoid letting it inspect your installed skills or username unless you want that personalization, and approve any outbound messages, quote requests, bookings, or listen-mode use explicitly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill instructs the agent to inspect the local skills directory, system username, and conversation content to infer a user profile, which goes beyond simple discovery/publishing. Even though consent is mentioned earlier, the profiling scope is broad and collects host-environment data not strictly necessary for the core function.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The documentation claims the skill 'only handles discovery,' but elsewhere it instructs the agent to send `--help` and follow-up commands to external agents. That inconsistency can mislead users and reviewers about the actual operational scope, increasing the risk of unintended command execution against third-party services.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The top-level description says to use the skill whenever users want to find someone, a service, help, or publish an agent, which is broad enough to trigger on many ordinary conversations. Overbroad activation criteria can cause the skill to run unexpectedly and expose user queries or perform network actions without clear intent.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The 'core principle' says any expression of wanting to find an agent/service/information should cause a Yellow Pages search automatically. This lacks meaningful activation boundaries and can lead to unsolicited external lookups based on casual or exploratory conversation.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes scanning installed skills and the system username to infer interests and identity signals, but does not provide a concrete, prominent privacy warning describing this sensitive collection in place. Users may consent to 'analysis' without understanding that local filesystem contents and OS identity are being inspected.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The workflow instructs the agent to send `--help` and then additional inquiry commands to third-party agents on the user's behalf, but it does not require a clear warning or per-action confirmation before these messages are sent. This can disclose user interests, location, budget, and other business context to external parties without sufficiently informed consent.

Ssd 3

Medium
Confidence
95% confidence
Finding
The skill explicitly directs the agent to inspect installed skills, the system username, and conversation details to build a user profile. This is sensitive host and behavioral profiling that can reveal personal identity, profession, interests, and installed tooling, creating unnecessary privacy and reconnaissance risk.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.