Back to skill

Security audit

Aws Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This AWS helper is mostly coherent, but it asks for powerful cloud access while using overly broad activation wording and weak guardrails for destructive AWS changes.

Install only if you intend to let the agent operate AWS resources from your local credentials. Use a least-privilege IAM profile, avoid root or broad admin keys, do not paste secrets into prompts or logs, and require explicit confirmation before create, delete, stop, IAM, security group, or VPC changes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The skill's activation description is overly broad, explicitly covering generic coding, debugging, testing, and deployment requests rather than narrowly scoping to AWS infrastructure tasks. In an agent environment, this can cause the skill to activate in unrelated contexts and gain access to read/write/exec capabilities, increasing the chance of unintended infrastructure actions or exposure to sensitive deployment workflows.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The coverage keywords massively expand trigger scope with vague phrases and duplicated general-purpose terms, effectively telling the agent this skill applies to many unrelated developer tasks. Because the skill also exposes exec/write tooling and can operate on cloud resources, ambiguous auto-selection materially increases the risk of accidental invocation and unintended command execution in privileged environments.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation presents destructive operations such as deleting or modifying AWS resources without a prominent warning about irreversibility, service disruption, or billing impact. In cloud contexts, users may trigger deletion or network changes that cause outages, data loss, or unexpected charges, especially when paired with an exec-capable skill.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill instructs users to configure AWS access keys and secret keys but does not provide a strong privacy warning against exposing, logging, echoing, or embedding those secrets in prompts, code, or output. Given the skill's purpose and available tools, mishandling cloud credentials could lead to full account compromise, unauthorized resource creation, data access, and financial abuse.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.