Back to skill

Security audit

Ai Assistant Free

Security checks across malware telemetry and agentic risk

Overview

This document-analysis skill is mostly coherent, but it asks for broad command execution and includes network troubleshooting without clear limits.

Install only if you are comfortable granting the skill command-execution capability. Prefer running it on documents you intentionally provide, and avoid letting it execute troubleshooting or file-processing commands unless you have reviewed the exact command first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill declares unrestricted `exec` even though its stated purpose is document analysis, and it explicitly recommends running `ping` and checking firewall/proxy settings during error handling. This expands the agent's capabilities beyond what is necessary, creating avoidable command-execution and network-touching behavior that could be abused through prompt injection or misdirected troubleshooting flows.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.