Back to skill

Security audit

agent

Security checks across malware telemetry and agentic risk

Overview

This skill is a persona/agent-definition prompt, but it asks for broad file, command, and API authority that is not clearly needed for that purpose.

Review before installing. This does not show destructive or exfiltration behavior, but it asks for powerful tools that are not well scoped to the stated agent-persona purpose. Install only if you are comfortable granting filesystem write access, shell execution, and ambiguous API/credential use, or constrain those permissions before use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The skill is declared as an agent/persona-definition capability, but later documents unrelated powers including file handling, external API use, and command execution. This mismatch expands the implied trust boundary and can mislead operators into granting powerful tools to a skill whose stated purpose does not require them, increasing the risk of privilege misuse or prompt-to-action abuse.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
Documenting system command execution for a skill intended to define identity, voice, and boundaries is unnecessary and dangerous. In an agent environment, normalizing exec as part of this skill can lead to arbitrary command execution if the skill is invoked with untrusted content or if users assume the documented behavior is safe and intended.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
File processing and write access are broader than necessary for a persona-definition skill and create opportunities for unauthorized file modification or data exposure. Even absent explicit exploit code, overbroad capability claims can cause the platform or operator to enable write access that an attacker could later abuse through prompt injection or workflow confusion.

Context-Inappropriate Capability

Medium
Confidence
85% confidence
Finding
External API integration is described despite not being necessary for defining agent persona, which widens the attack surface and raises the risk of data exfiltration to remote services. Users may provide sensitive prompts or configuration data, and unclear remote-calling behavior undermines informed consent and least privilege.

Vague Triggers

Medium
Confidence
75% confidence
Finding
The invocation description is overly broad, covering general AI model calling, dialogue, orchestration, and LLM application use. Ambiguous scope makes it easier to apply the skill in contexts far beyond its stated role, which can mask privilege creep and make dangerous capabilities appear legitimate.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.