Back to skill

Security audit

Book Illustrator Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a book-illustration planning guide, but it asks for write and shell-command authority and includes loosely scoped activation and outbound-callback language that users should review before installing.

Install only if you are comfortable with a book-illustration helper having write and shell-command permissions. Prefer a version that removes exec, narrows activation to book-illustration tasks, and explains any callback behavior before using it with private manuscripts or project files.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (8)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill claims it is a Markdown-only assistant that does not upload data, yet it documents exec-based network troubleshooting such as running ping and discussing firewalls/proxies. This creates a trust and capability mismatch: users may invoke a skill they believe is passive while it can trigger command execution and network interactions.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
A book illustration planning skill has no clear functional need for shell execution, yet the manifest grants exec capability. Unnecessary powerful permissions expand the attack surface and could allow harmful filesystem or command execution if the skill is invoked with adversarial or malformed input.

Intent-Code Divergence

Low
Confidence
76% confidence
Finding
The documentation says no data is uploaded, but the input model includes a callback_url for asynchronous notifications. Even if optional, a callback mechanism implies potential outbound transmission and can mislead users about privacy and data flow.

Intent-Code Divergence

Low
Confidence
74% confidence
Finding
The skill asserts that it does not upload data, yet its troubleshooting guidance includes network connectivity testing and firewall/proxy discussion. While ping itself may be limited, the documentation still signals outbound network behavior inconsistent with the privacy claim.

Vague Triggers

Medium
Confidence
84% confidence
Finding
The activation text is broad enough to match generic project management, task planning, and team collaboration requests unrelated to book illustration. Overbroad triggering can cause the wrong skill to activate in unrelated contexts, increasing the chance that unnecessary write/exec capabilities are exposed or used.

Vague Triggers

Medium
Confidence
82% confidence
Finding
The capability coverage keywords include vague, generic phrases that can over-trigger the skill outside its intended domain. In combination with elevated tools like write and exec, this increases the risk of unintended activation and misuse.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill advertises write and exec capabilities but provides no warning about filesystem changes or command-execution effects. Users may reasonably assume a content-planning assistant is non-invasive, so missing disclosure materially increases the risk of unsafe or surprising side effects.

Missing User Warnings

Medium
Confidence
81% confidence
Finding
The documented callback URL enables outbound communication but lacks any privacy, security, or transmission warning. This can expose user data, metadata, or task results to third-party endpoints without informed consent or validation safeguards.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.