Back to skill

Security audit

Chat Agent Tool Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly a temporary chat-room guide, but its activation instructions are mismatched and it encourages public tunnel exposure with weak examples and incomplete safety guidance.

Review before installing. Use this only when you intentionally want a temporary chat room, prefer localhost unless remote access is necessary, use a strong unique password, stop the service when done, and do not rely on the file-processing trigger text because it appears copied from an unrelated skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (4)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill’s “不适用场景” and “触发条件” sections conflict with the rest of the document by describing file-processing and document-conversion use cases instead of a temporary chat service. This can cause agents to invoke the skill in the wrong contexts, potentially exposing chat functionality or public tunnel features when the user requested unrelated file tasks, undermining safe tool selection and user intent boundaries.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger condition says the skill should be used for file processing, document conversion, format conversion, and content extraction, which is unrelated to the actual chat-room functionality. In agent ecosystems, overly broad or incorrect trigger conditions can cause unsafe autonomous invocation, leading the agent to launch network services or expose tunnels during workflows that never required external communication.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill promotes exposing the local chat service via cloudflared/ngrok to the public Internet, but it does not clearly warn that doing so expands the attack surface, may leak sensitive conversations, and turns a local ephemeral tool into a remotely reachable service. In this skill’s context, tunnel exposure is central functionality, so missing security guidance is more dangerous because users may treat it as safe-by-default.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The examples use simple sample passwords such as 'dev123' and 'prod456' without an immediate, prominent warning that they are demonstrative only and unsafe for real use. Because this skill can expose a live chat service locally or via public tunnels, users may copy-paste these credentials into practice, making unauthorized room access or trivial guessing more likely.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.