Back to skill

Security audit

api-and-interface-de

Security checks across malware telemetry and agentic risk

Overview

The skill is packaged as API/interface design guidance but asks for broad read and command-execution capability and describes generic automation, file, credential, API, and command workflows.

Install only if you are comfortable reviewing this as a broad automation skill with read and command-execution access, not as a narrow API design helper. It should be narrowed to API/interface design guidance or clearly re-scoped with explicit command, file, credential, and network boundaries before routine use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as API/interface design guidance, but its manifest and body claim broad automation, data processing, API connectivity, file handling, and execution behaviors. This mismatch expands the effective trust boundary: users and orchestrators may grant powerful capabilities under a benign-seeming label, enabling misuse or accidental execution beyond the expected design-assistance scope.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
The declared exec capability is not justified for a skill whose stated purpose is design guidance. Unnecessary command execution materially increases risk because any downstream implementation may invoke shell/system commands, creating a path to command injection, local file tampering, or host compromise if user-controlled inputs are later introduced.

Context-Inappropriate Capability

High
Confidence
95% confidence
Finding
The documentation describes unrelated capabilities including workflow orchestration, file operations, credential setup, network/API use, and command troubleshooting, all of which imply operational behaviors far beyond interface-design advice. In context, this makes the skill more dangerous because broad, ambiguous capability claims can normalize risky actions and cause operators or agents to over-authorize the skill.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill's name and summary imply a focused design-assistance tool, while the body describes a generic automation/data-processing skill with a different intent. This identity mismatch is dangerous because reviewers and users may underestimate what the skill can do, leading to inappropriate trust, invocation, or permission assignment.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger condition 'when the user needs to perform related operations' is so broad that it can match many unrelated situations. For a skill already describing oversized capabilities, ambiguous triggering increases the chance of unintended invocation, which can expose files, credentials, or execution paths without clear user intent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.