Back to skill

Security audit

Automation Workflows

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a Markdown automation guide, but it asks for broad command-execution authority and uses very broad trigger words without clear limits.

Review this before installing because it can route broad requests into an automation skill that has command-execution access. Only use it when you explicitly want workflow automation help, and avoid letting it run commands or change connected business systems unless you have reviewed the exact action first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill metadata and description repeatedly claim that risky code and external dependency risks were removed, yet the manifest still grants the exec tool, which enables arbitrary command execution and side effects on the host. This discrepancy can mislead reviewers and users into trusting the skill more than warranted, reducing scrutiny around a powerful capability.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The documentation frames the skill as Markdown-driven and says no extra API key is needed, which suggests low operational risk, but the manifest includes exec, allowing system-level actions independent of API credentials. That can create a false sense of safety and lead operators to approve or run the skill without recognizing that it can still modify files, invoke programs, or affect the environment.

Vague Triggers

High
Confidence
83% confidence
Finding
The trigger keywords 'save, workflows, implement, automation, design' are extremely broad and likely to match ordinary user conversation, causing unintended activation of this skill. In combination with the declared exec capability, accidental routing into this skill raises the chance that the agent may take or propose side-effecting actions in contexts where the user did not intend to invoke it.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.