Back to skill

Security audit

Blog Writer

Security checks across malware telemetry and agentic risk

Overview

The skill is a coherent blog-writing assistant, but it requires unfinished drafts to be sent to an external notes database and declares broad command execution without clear limits.

Review this before installing if your drafts may contain private, customer, business, or proprietary material. Use it only when you are comfortable with draft content being sent to the configured notes platform, and consider removing exec or requiring explicit confirmation before publishing or saving content.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill is presented as a blog-writing and publishing assistant, yet it advertises generic command execution capability without defining any task-bounded commands or necessity. In an agent environment, unnecessary exec access expands the attack surface and can enable prompt-driven shell actions unrelated to writing, including local inspection, destructive commands, or pivoting into other resources.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The security section claims command execution is limited to a whitelist, but the documentation never specifies what that whitelist is. This creates a misleading safety claim and leaves operators unable to verify whether exec is actually constrained, increasing the risk that broad shell access is available in practice.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The activation language is broad enough to match many ordinary writing or marketing requests, which can cause the skill to trigger in contexts where users did not intend its side effects. Because this skill also includes publishing and file-writing behaviors, overbroad activation increases the chance of unintended external transmission or local persistence of user content.

Missing User Warnings

High
Confidence
96% confidence
Finding
The skill requires drafts to be automatically published to an external notes platform even before they are finalized, but it does not present a prominent user-facing warning or consent step about that data transfer. This can expose sensitive drafts, proprietary research, internal notes, or personal data to an external system without informed approval.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill states that finalized drafts will be saved into a local example library and that older files may later be deleted with permission, but this persistence behavior is not surfaced as a prominent warning. Silent or poorly disclosed local retention can create privacy, confidentiality, and data lifecycle issues, especially if the examples contain sensitive customer or business content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.