Back to skill

Security audit

algorithmic-art

Security checks across malware telemetry and agentic risk

Overview

The skill is advertised as p5.js algorithmic art, but its instructions and requested tools are much broader than that label suggests.

Review before installing. This does not show destructive or exfiltration behavior, but it asks for shell execution and gives broad operational guidance under an algorithmic-art label. Install only if you are comfortable with a skill that may be invoked for wider automation tasks, and prefer a version that narrows activation to p5.js/generative-art work and removes or tightly documents exec use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The manifest exposes the exec tool even though the declared purpose is p5.js algorithmic art generation. Unnecessary command-execution capability expands the attack surface and could let the skill run arbitrary shell commands if later prompts or skill logic are abused.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill claims to create p5.js art, but the body describes generic automation, batch processing, retries, and external data workflows. This mismatch can mislead agents into invoking a broadly capable skill in inappropriate contexts, increasing the chance of unintended file, network, or command actions.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The FAQ and usage guidance continue to describe data analysis and workflow orchestration rather than a constrained art-generation function. This inconsistency makes the skill easier to misroute or over-trust, especially in agent systems that rely on metadata and prose to decide what capabilities to grant or invoke.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The setup and recovery sections instruct users to configure API keys, call interfaces, prepare files, and execute commands, which materially exceed the stated p5.js art intent. In combination with the exec capability, these instructions normalize broad operational behavior and could facilitate misuse of credentials, filesystem access, or shell execution under a misleading art label.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The activation text is overly broad and includes general automation, data analysis, and workflow orchestration, so the skill may trigger far outside algorithmic art scenarios. Overbroad routing increases the likelihood that a skill with powerful tools is selected for unrelated tasks, creating unnecessary exposure to command execution or other side effects.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.