Back to skill

Security audit

Auto Monitor Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is a disclosed single-machine monitoring skill with some sloppy scope wording and optional external notifications, but no hidden, destructive, or deceptive behavior was found.

Install only if you want a basic local monitoring helper. Keep it scoped to explicit system status, process, disk, network, history, and alert tasks; review any SMTP or callback configuration because those notifications can expose host details outside the machine.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The description repeatedly uses broad 'Use when 需要系统监控、日志分析、运维告警、部署管理时使用' phrasing without meaningful trigger boundaries, which can cause the agent to invoke this skill for a wide range of generic operations tasks. Because the skill has exec capability, overbroad routing increases the chance of unnecessary command execution in contexts the user did not specifically intend.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The capability coverage section enumerates many fragmented and highly generic keywords, including common operations and workflow terms, which makes accidental matching more likely during skill selection. In combination with read/exec tools, this broad matching can lead to the skill being chosen for everyday requests outside its true scope, expanding the attack surface for unintended execution.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documented callback_url parameter introduces external data transmission behavior but does not warn that monitoring results or metadata may be sent to a remote endpoint. Without explicit disclosure and validation requirements, users may unknowingly exfiltrate system information to untrusted URLs or permit SSRF-like behavior in implementations derived from this documentation.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents email alerting and SMTP credential use without clearly warning that monitoring data and secrets will be transmitted to external infrastructure. This can lead users to configure sensitive credentials and operational telemetry without understanding the privacy and security implications, especially in agent-driven workflows.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.