Back to skill

Security audit

ai-capabilities

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed AI capability wrapper whose file writes, local persona reads, and API key use fit its stated persona, voice, and image-generation purpose.

Install only if you want a broad AI-capability router that can call configured MCP services, use your SiliconFlow key for generation, and update local persona state files such as SOUL.md. Review persona-changing requests before running them because they can affect future agent behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill metadata includes a very broad trigger list such as 'AI能力', '语音合成', and '图像生成' without clear scope boundaries or disambiguation rules. This can cause over-activation in unrelated conversations, increasing the chance that a high-privilege skill with read/write and AI-generation capabilities is invoked unexpectedly and performs actions the user did not intend.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill declares write capability and reliance on sensitive configuration/environment data, including file-modifying tools and SILICONFLOW_API_KEY, but the user-facing documentation does not warn that the skill may modify local persona/state files or consume privileged external-service credentials. In this context, the skill also exposes tools that explicitly write to SOUL.md and likely other state files, making silent invocation or indirect use more risky.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.