Back to skill

Security audit

文档扫描增强

Security checks across malware telemetry and agentic risk

Overview

This document-image tool discloses remote image processing, but it also includes overbroad activation text and examples that normalize removing watermarks and exam answers.

Review this skill carefully before installing. It may be useful for authorized document cleanup, but avoid using it on sensitive documents unless you trust the external scanning service, and do not use the watermark or exam-answer removal workflows to strip attribution, bypass rights, or alter assessment materials deceptively.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Intent-Code Divergence

High
Confidence
89% confidence
Finding
The skill is marketed as an image/document enhancement tool, but the paid-feature section introduces unrelated security capabilities like vulnerability scanning, compliance auditing, and threat-intel alerting. This kind of domain mismatch is dangerous because it can cause overbroad invocation, user confusion, and inappropriate trust or delegation to a skill that also has exec capability.

Vague Triggers

High
Confidence
91% confidence
Finding
The description includes an overly broad invocation phrase covering code generation, programming assistance, debugging, testing, and deployment, which is unrelated to document scanning. In an agent ecosystem, this can cause the skill to activate in far more contexts than intended, exposing file, exec, and network-linked behavior to unrelated user tasks.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The fallback rule activates whenever a user generally asks to optimize a document image without a precise scene, which is broader than necessary and can cause the skill to run on ambiguous requests. In the presence of exec and external API use, ambiguous activation increases the chance of unintended data handling or off-target tool use.

Ssd 4

Medium
Confidence
87% confidence
Finding
The skill explicitly promotes removing handwritten answers from completed test papers to recreate a blank exam sheet. This facilitates deceptive document alteration and academic fraud, and the context makes misuse plausible because the capability is framed as a normal supported workflow.

Ssd 4

Medium
Confidence
93% confidence
Finding
The skill normalizes watermark removal as a standard feature, including examples removing website watermarks, which can enable copyright infringement, attribution stripping, and deceptive redistribution. This is especially concerning because the documentation operationalizes the misuse rather than limiting it to authorized restoration scenarios.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.