Back to skill

Security audit

Afrexai Knowledge Management

Security checks across malware telemetry and agentic risk

Overview

This knowledge-management skill is not clearly malicious, but it asks for broad read/write/exec authority and vague API/credential use beyond its documented scope.

Review this skill carefully before installing. Use it only in a constrained workspace, provide least-privilege API credentials only when a specific integration is needed, and require explicit approval before any file writes, external callbacks, API calls, or shell commands. Avoid storing personal or performance-adjacent employee details unless your organization has clear consent, retention, and access-control rules.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The skill is framed as knowledge management, but it advertises broad file processing, API integration, and shell execution capabilities that materially exceed that scope. This kind of capability overreach is dangerous because it can normalize high-risk actions under an innocuous label, increasing the chance an agent will read, modify, or execute on local or external resources without the user understanding the blast radius.

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The efficiency table markets generic automation functions such as batch file handling, multi-interface aggregation, and command execution that are not tied to the stated purpose of knowledge management. This broadens operator expectations and can encourage unsafe invocation patterns where a user or agent treats the skill as a general automation runner with access to sensitive files, commands, or services.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
Documenting command execution as a built-in capability for a knowledge-management skill introduces unnecessary remote-action risk. In this context, shell execution is especially dangerous because the surrounding documentation does not define strict boundaries, allowed commands, or approval requirements, so an agent could be induced to run destructive or data-accessing commands under a benign-seeming task.

Context-Inappropriate Capability

Medium
Confidence
82% confidence
Finding
The documentation makes external API use and API key setup part of normal operation even though the skill's main purpose is organizational knowledge management. That mismatch increases the risk of unnecessary credential collection, overprivileged integrations, and accidental data disclosure to third-party services, especially if users assume the skill is only local and documentation-oriented.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill describes writing files, calling APIs, and executing commands without pairing those actions with clear warnings, consent boundaries, or impact disclosures. In an agent setting, omission of these guardrails is dangerous because users may not realize the skill can change local state, contact external services, or run commands with side effects.

Ssd 3

Medium
Confidence
89% confidence
Finding
The workflow normalizes retention of employee confusion points, unanswered questions, and role-specific knowledge into persistent artifacts without discussing consent, minimization, sensitivity review, or retention limits. In a real organizational setting, this can lead to unnecessary collection of personal, performance-adjacent, or sensitive operational information that may later be exposed, misused, or retained beyond legitimate need.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.