Back to skill

Security audit

Can Bus Toolkit

Security checks across malware telemetry and agentic risk

Overview

The skill describes a plausible CAN-bus provenance/audit tool, but it asks for broad execution authority while enabling networked adapters, webhook alerts, persistence, and rollback behavior without tight user-controlled boundaries.

Review this skill before installing in a real workspace. Only use it with explicit configuration for which logs, adapters, webhooks, OTS servers, output paths, snapshots, and rollback actions are allowed. Avoid enabling automatic rollback, webhook alerts, HTTP/A2A/MCP interception, or broad indexing until you have confirmed the exact data flows and approval steps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The documented output schema is unrelated to the advertised CAN-bus provenance functions and instead describes a generic scoring/audit response. This mismatch can cause an agent to route sensitive provenance tasks through the wrong execution path, mis-handle results, or silently apply a grading workflow where operational actions were expected, increasing the chance of unsafe behavior and user deception.

Intent-Code Divergence

Medium
Confidence
98% confidence
Finding
The input schema requests generic review parameters such as content and strictness rather than parameters for CAN-bus provenance operations. This inconsistency can cause an agent to invoke the skill on arbitrary text or broad inputs, making unintended execution more likely and obscuring what data will be processed or transmitted.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The invocation language is broad ('parse user instructions, execute core operations') and lacks strict trigger boundaries or confirmation requirements. In a skill with exec capability and support for networked adapters, this can let loosely phrased user input activate state-changing actions, external communications, or other unsafe operations without clear consent.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill describes OTS synchronization and automated alerting/webhook behavior without prominent user warnings that data may be sent to third-party services or enterprise endpoints. Because the skill includes exec and multiple transport adapters, hidden network egress can expose sensitive timing, hash, log, or operational metadata and may trigger unintended outbound communications.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
The skill advertises automatic rollback and audit report export without clear warnings about local state modification, snapshot restoration, or file creation. In practice, rollback can overwrite or revert data and exports can write sensitive audit information to disk, creating integrity, confidentiality, and operational risks if triggered unexpectedly.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.