Back to skill

Security audit

Audit Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

The skill is an audit-reporting framework, but it asks for broad write/exec authority and persistent evidence logging for sensitive audit data without clear limits or retention controls.

Review before installing. Use it only on audit data you are allowed to store locally, avoid providing secrets unless necessary, and require explicit confirmation before any shell command or callback URL use. Treat its reports as templates and analysis guidance, not as cryptographic certification or a substitute for a scoped professional audit.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a bounded audit/verification toolkit, but its manifest grants both write and exec capabilities, which materially expand it into arbitrary system modification and command execution. In an agent environment, this mismatch can cause over-trusting invocation, enabling filesystem changes or shell actions unrelated to auditing and increasing the blast radius if prompted with adversarial input.

Intent-Code Divergence

Medium
Confidence
78% confidence
Finding
The manifest markets the skill for encryption/protection use cases, while later sections state the free edition does not support cryptographic certification/signing. This inconsistency can mislead users into relying on protections the skill does not actually provide, creating false assurance around integrity or security-sensitive workflows.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation language is broad enough to match many generic requests involving safety checks, compliance, scanning, or protection. In an agentic routing context, this can cause the skill to be invoked outside its intended narrow use cases, especially given its exec/write permissions, increasing the chance of unnecessary access or risky actions.

Vague Triggers

Medium
Confidence
82% confidence
Finding
Claiming applicability to virtually any scenario involving verification, risk identification, or compliance creates an overbroad invocation scope. This makes accidental or excessive routing more likely and encourages users or orchestrators to trust the skill in contexts where its controls, privacy posture, or domain assumptions may not be appropriate.

Missing User Warnings

Medium
Confidence
80% confidence
Finding
The skill accepts callback URLs and mandates local evidence logging, but does not disclose privacy, retention, or data handling risks. In auditing contexts, inputs may include code, contracts, financial data, prompts, or other sensitive records, so silent storage or callback transmission can expose confidential information or create compliance issues.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.