Back to skill

Security audit

baoyu-diagram

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a diagram-generation skill, but it requests broad read/write/command authority and describes generic file, API, and command operations without clear limits.

Review this skill carefully before installing. It may be useful for generating SVG diagrams, but only grant file, API, or command-execution access if you are comfortable with broad agent authority and can supervise what files, commands, credentials, and external services are used.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is declared as a diagram generator, but its description also advertises generic data analysis, reporting, statistical insight, and visualization use cases. This scope expansion creates misleading capability boundaries and can cause an agent to invoke the skill in contexts far beyond its stated purpose, increasing the chance of unexpected data handling or privilege use.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The documentation claims command execution, file processing, and external API integration even though the skill's core purpose is diagram generation. In an agent environment with read/exec/write tools, this overbroad framing can normalize powerful actions without necessity, making it easier for the skill to be invoked with excessive privileges or to process sensitive local data unexpectedly.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The file sends contradictory intent signals: early sections present a narrow diagram tool, while other sections broaden it toward generic automation behavior. Contradictory documentation is dangerous in agentic systems because tool-selection and user trust may rely on these descriptions, leading to misuse of available read/write/exec capabilities under an innocuous label.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation language is overly broad and lacks clear trigger constraints, encouraging the agent to select the skill for loosely related tasks. In practice, broad routing criteria increase unintended activation, which is riskier here because the skill advertises access to powerful tooling and mixed-purpose workflows.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The markdown describes file handling, API calls, and command execution without prominent user-facing warnings about side effects, data exposure, or system impact. In a skill with read/write/exec tools, omission of these warnings can lead users and orchestrators to treat risky operations as routine, increasing the chance of unauthorized file access, external data transfer, or command misuse.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.