Back to skill

Security audit

Auto File Organizer Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly a local file organizer, but it asks for file mutation and command execution while its routing, deletion, and callback/network language are broader than its stated purpose.

Review this before installing if you expect a narrow local organizer. Use preview mode first, restrict it to folders you intentionally choose, avoid using callback_url, and do not enable deletion/cleanup behavior unless you have a backup and the exact behavior is clear.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims it runs locally, requires no extra API key, and does not upload file data, yet it also declares an LLM API as a required dependency and includes callback/network-oriented inputs. This contradiction can mislead users and agents into authorizing network access or external data flow that they would not otherwise permit, undermining informed consent and trust boundaries.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The FAQ states the organizer 'does not delete any files,' but then says deletion of temporary files can be enabled via configuration. Conflicting statements about destructive behavior are dangerous because users may run a file-moving skill under false assumptions, leading to unintended data loss if deletion features exist or are later enabled by an agent or bundled config.

Context-Inappropriate Capability

Low
Confidence
83% confidence
Finding
Introducing callback URLs and network-oriented behavior into a local file-organization skill expands the attack surface without a clear functional need. Even if not directly malicious, such fields can normalize outbound communication paths that may leak metadata, task results, or file-related information to untrusted endpoints.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger condition says to use this skill for broad tasks such as file processing, document conversion, format conversion, and content extraction, which exceed the documented capabilities of a file organizer. Overbroad routing criteria are dangerous because an agent may invoke a tool with read/write/exec privileges in contexts the user did not intend, increasing the chance of unnecessary filesystem modification or command execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.