Back to skill

Security audit

Board Art Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a pixel-art canvas tool, but it asks for exec/write authority and includes unclear or mismatched instructions that could cause unintended shared-canvas changes.

Review this skill before installing. It may be useful for personal pixel-art publishing, but only use it when you intentionally want an agent to access a canvas service, use a token, and make shared-canvas changes. Avoid relying on its broad project-management trigger, and confirm any publish, delete, import, or export action manually.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill metadata frames the free edition as a narrowly scoped personal publish/view tool, but the body broadens behavior to generic create/query/modify/delete plus import/export/save operations. This scope expansion can cause an agent to over-authorize or invoke state-changing actions beyond user expectations, increasing the chance of unintended destructive operations.

Vague Triggers

High
Confidence
96% confidence
Finding
The trigger condition says to use the skill for project management, task planning, progress tracking, and team collaboration, which is unrelated to a pixel-art publishing tool. Overbroad triggers can cause an agent to select this skill in the wrong context and execute write or exec-capable actions against a shared canvas service when the user intended an entirely different workflow.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The markdown describes publish and delete-capable behavior without clear safety prompts or warnings that these actions change shared remote state and may be hard to reverse. In an agent setting with exec/write tools, missing confirmation language increases the risk of accidental publication, overwrite, deletion, or backup export without informed user consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.