Skill Evaluator

Security checks across malware telemetry and agentic risk

Overview

This is a local skill-quality evaluator that reads a chosen skill folder and reports issues, with no hidden persistence, credential use, or exfiltration found.

Safe to install as a local skill review aid. Run the evaluator only on skill folders you intend to inspect, review any generated EVAL.md before publishing it, and use the optional pip or npx tools only in an environment where you trust those third-party packages.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
89% confidence
Finding
The skill advertises and instructs use of local scripts and external tooling that imply shell execution, file reads, environment access, and possible network use, yet it declares no permissions or capability boundaries. This mismatch can cause reviewers or runtime policy systems to underestimate what the skill may do, increasing the risk of unintended execution, data exposure, or overbroad trust during evaluation.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The manifest description uses very broad activation language such as 'review, audit, evaluate, score, or assess a skill before publishing,' which can match many generic requests. Overbroad triggers can cause the skill to activate in contexts where the user did not intend it, increasing prompt-surface exposure and the chance that its instructions or scripts are applied to untrusted content unnecessarily.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal