Back to skill

Security audit

Api Magic Gen

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a magic-api configuration guide, but its broad activation text, unrelated review-scoring sections, and exec-enabled troubleshooting make its scope unclear enough to require review before installation.

Review this skill before installing. It does not appear malicious, but it should be narrowed to magic-api tasks, remove unrelated review-scoring and generic troubleshooting sections, and require explicit user confirmation before running commands or changing deployment/configuration files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The input/output section documents a completely different code-review scoring workflow than the rest of the skill, which claims to be a professional magic-api generation/configuration skill. This kind of semantic mismatch can cause an agent to invoke the wrong behavior, mishandle sensitive user input, or execute unintended tool paths under false assumptions about the skill’s purpose.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The error-handling guidance tells the agent to perform network troubleshooting and rerun commands even though this skill is presented as documentation/configuration guidance for magic-api. In an agent context with exec enabled, unrelated operational instructions can trigger unnecessary command execution, expanding the attack surface and allowing prompt content to steer the agent into risky system actions.

Intent-Code Divergence

High
Confidence
94% confidence
Finding
The later error section shifts the skill’s apparent purpose again, referring to LLM response failures and command execution problems instead of the advertised magic-api product guidance. This inconsistency increases the chance that an agent treats the file as a general-purpose operational runbook and executes commands or follows fallback behaviors that were never intended by the user.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The invocation text uses broad trigger language like system monitoring, log analysis, alerting, and deployment management, which goes far beyond a narrowly defined API-generation skill. Overbroad activation criteria make accidental or adversarial invocation more likely, especially in agent frameworks that select skills based on natural-language matching.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The capability coverage section contains fragmented, ambiguous keyword-like phrases that resemble broad trigger terms rather than precise capability descriptions. In retrieval or auto-selection pipelines, such loose terms can cause the skill to match unrelated user requests and expose tools or workflows outside its intended context.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.