Back to skill

Security audit

Art Creator Free

Security checks across malware telemetry and agentic risk

Overview

This looks like an art guidance skill, but its declared command/write authority and broad AI-agent routing language are not well scoped to that purpose.

Review before installing. The art-coaching content itself is not destructive, but the skill should be narrowed to art tasks, avoid broad exec/write authority unless clearly needed, and clarify whether callbacks or model providers receive user input.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The manifest markets this as an art-creation assistant, but the description and declared tools also position it for generic AI model calling, agent orchestration, and command execution. That scope mismatch can cause the skill to be invoked outside its intended domain, exposing powerful capabilities like exec in contexts where users would not expect them.

Intent-Code Divergence

Medium
Confidence
85% confidence
Finding
The free-version limitations say personalized practice-plan generation is unsupported, yet examples instruct the assistant to generate tailored first-week and multiweek plans. This inconsistency can mislead users and downstream agents about what the skill is allowed to do, increasing the chance of unintended behavior or overbroad invocation.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill states that no data is uploaded, while also saying it is for AI model calling and LLM applications, which normally involve transmitting prompts to a model provider. This is dangerous because users may disclose sensitive content under a false privacy expectation.

Vague Triggers

High
Confidence
94% confidence
Finding
The activation guidance is overly broad and includes generic AI/agent use cases unrelated to art guidance. In a skill with read/write/exec tools, broad triggering materially increases the risk of accidental or inappropriate activation in sensitive workflows.

Vague Triggers

High
Confidence
96% confidence
Finding
The capability keywords are excessively broad and include generic terms such as model calling, intelligent dialogue, Agent, and LLM application. This can cause unintended routing or selection of the skill for arbitrary tasks, which is especially risky because the manifest exposes exec and write capabilities.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The documented callback_url introduces external network transmission, but elsewhere the file claims no data is uploaded. This mismatch can lead users to provide inputs without understanding that task data or results may be sent to an external endpoint.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.