Back to skill

Security audit

assistant

Security checks across malware telemetry and agentic risk

Overview

This assistant skill is not clearly malicious, but it asks for broad file-writing and command-execution authority that is not tightly scoped to task, communication, or scheduling use.

Review this skill carefully before installing. It may be acceptable only if you are comfortable giving a general assistant permission to modify files, run commands, call external APIs, send messages, and perform deletes; otherwise, prefer a version that removes exec/write access or clearly limits commands, file paths, services, and destructive actions to explicit user-approved operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a personal task/scheduling assistant, but later documentation expands its scope to generic file handling, API integration, and command execution. This capability mismatch can mislead users and reviewers about the real trust boundary, increasing the chance that dangerous operations are invoked under an innocuous assistant label.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
System command execution is a powerful primitive that is not justified by the stated assistant role of managing tasks, communications, and scheduling. If exposed through a broadly described assistant skill, it can enable unintended local command execution, environment inspection, or destructive actions far beyond user expectations.

Context-Inappropriate Capability

Low
Confidence
82% confidence
Finding
Generic read/write capability is broader than necessary for a scheduling and communications assistant and enlarges the data exposure and modification surface. While not inherently exploitable on its own, the mismatch creates unnecessary access to local data and the ability to alter files without clear role justification.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill advertises write, API, and command execution capabilities without a prominent user-facing warning about possible system, file, or data impact. This increases the risk of unsafe use because users may not realize the skill can modify local state, invoke external services, or execute commands.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The operational workflow explicitly includes create, modify, query, and delete API actions but does not warn users about destructive changes or external side effects. In an assistant context, this can lead to accidental deletions or unauthorized state changes because the action model appears routine and underexplained.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.