Back to skill

Security audit

canvas-design

Security checks across malware telemetry and agentic risk

Overview

This skill is branded as a canvas design tool but asks for broad command-execution authority and describes API credentials, file handling, development automation, and operations workflows without clear limits.

Review carefully before installing. This is not just a design helper as written: it asks for command execution and discusses API credentials and external connections. Only install it if you are comfortable granting those capabilities, and prefer a narrower design-only skill if you do not need development automation or command execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (7)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill makes strong security and integrity assurances while the same file documents broad command execution, API usage, credential handling, and external connectivity. These unsupported claims can mislead users and downstream agents into granting more trust than warranted, increasing the chance that risky capabilities are used without proper scrutiny.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest presents the skill as a visual art or canvas design tool, but the body describes general development automation, data analysis, workflow orchestration, API calls, and command execution. This scope mismatch is dangerous because agents or users may invoke a seemingly harmless design skill while unintentionally authorizing far broader operational behavior.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Granting exec capability to a skill advertised for static visual art creation is unjustified and materially expands the attack surface. In this context, command execution could be used to run arbitrary local programs, manipulate files, or chain into further compromise under the cover of a benign design workflow.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill instructs users to configure API keys, establish connections, and execute commands even though its stated purpose is canvas design. This introduces unnecessary credential exposure and external data flow, making the skill more dangerous because a design-themed wrapper can obscure networked behavior and sensitive secret use.

Vague Triggers

High
Confidence
93% confidence
Finding
The activation guidance is broad and ambiguous, mixing design, development automation, data analysis, and workflow orchestration. Over-broad triggers increase the likelihood that the skill is invoked in inappropriate contexts, where its powerful capabilities such as exec or API use may be applied unexpectedly.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The applicable-scope section claims suitability for broad development, operations, and content-creation scenarios, which exceeds the stated design purpose. This creates a permission and expectation mismatch that can normalize use of a risky skill across unrelated tasks.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill describes API key setup, connection initialization, file handling, and command execution without an up-front warning that it may use credentials and run commands. Users may disclose secrets or enable powerful actions without informed consent, which is especially risky given the misleading design-oriented branding.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.