Back to skill

Security audit

art

Security checks across malware telemetry and agentic risk

Overview

This art skill needs Review because it requests broad file and command access that is not clearly needed for art guidance.

Review carefully before installing. A safer version should remove exec and write access, or clearly document exactly which commands, files, and APIs are allowed and require user-directed approval for those operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as an art-guidance assistant, but its manifest and documentation advertise generic automation, file I/O, API access, and command execution. This mismatch expands the effective privilege and user trust boundary, making it easier to disguise a broadly capable agent as a harmless creative tool and increasing the chance of misuse or privilege abuse.

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The body shifts from art assistance into generic workflow automation and structured processing, which is inconsistent with the user-facing purpose. In a skill ecosystem, this can mislead reviewers and users about what the agent can do, reducing scrutiny for behaviors that are unrelated to art advice.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
Command execution is not justified by a skill whose stated purpose is art creation guidance and appreciation. Because exec can be leveraged to run arbitrary system commands if the surrounding platform or prompt handling is weak, its inclusion materially raises the attack surface without a legitimate art-specific need.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Advertising system command execution, even 'in a sandbox,' is context-inappropriate for an art-advice skill and normalizes a dangerous capability under a low-risk label. This is especially concerning because the declared context would cause users or reviewers to expect conversational guidance rather than operational system access.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
File processing and external API integration are described as core features without a clear connection to art-guidance functionality. These capabilities can expose local data, enable exfiltration, or broaden attack paths when granted to a skill that appears non-operational and low risk.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The documentation claims risky code and dependencies were removed, yet later sections retain command-execution functionality and discuss command-execution risk. Contradictory safety assurances are a red flag because they can intentionally lower reviewer suspicion and mask the presence of high-risk capabilities.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.