Back to skill

Security audit

Aws Cloud Inspector Free

Security checks across malware telemetry and agentic risk

Overview

The skill is mostly an AWS CLI inspection guide, but it is labeled read-only while also allowing high-impact AWS changes and contains malformed broad capability text.

Install only if you are comfortable reviewing each AWS CLI command before execution. Use a dedicated read-only IAM role or profile, avoid production/admin credentials, and do not rely on the read-only label because the skill text also permits confirmed write and destructive operations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The skill markets itself as read-only but explicitly allows resource-changing AWS operations after confirmation. This mismatch is dangerous because downstream agents or users may trust the read-only label and invoke the skill in contexts where write access is not expected, enabling unintended destructive or privilege-impacting actions.

Intent-Code Divergence

High
Confidence
90% confidence
Finding
The document states it never reads or outputs credential files, yet later generated capability text references operating on aws/credentials. In an agent setting with exec and read tools enabled, contradictory instructions around credential files can cause an agent to inspect or expose sensitive AWS secrets despite earlier safety claims.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The capability section expands scope to create/modify/delete operations even though the skill is presented as read-only elsewhere. This is dangerous because broad action claims can steer an agent into performing mutating cloud operations under an over-trusted inspection skill, increasing the chance of destructive changes or configuration drift.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The skill includes broad natural-language trigger phrases and generic usage cues that are not tightly scoped to explicit AWS inspection intents. In agent ecosystems, overbroad activation criteria can cause the skill to engage on unrelated requests, increasing the odds of unnecessary credential use, unintended command execution, or invocation of the wrong capability.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.