Back to skill

Security audit

chat

Security checks across malware telemetry and agentic risk

Overview

This skill looks like a chat-style helper, but it asks for broad file, command, and API abilities that are not clearly scoped or justified.

Review this skill before installing. It may be acceptable only if you intentionally want a broad automation skill with filesystem, command, and API access; otherwise prefer a narrower chat-style preference skill that does not request exec/write permissions and that clearly states what data it stores or sends.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (7)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented primarily as a chat tone/style adaptation tool, but later advertises file handling, API access, and command execution. This capability mismatch can mislead users and host agents into granting broader privileges than necessary, increasing the attack surface and enabling unexpected system or data access.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
System command execution is not justified by the stated purpose of learning communication preferences and adapting reply style. Granting exec to a chat-oriented skill creates a path to arbitrary command execution, local data access, and environmental abuse if the skill is invoked with untrusted input or misused by an agent.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
Broad file read/write capability exceeds what is clearly needed for a chat preference adaptation skill. Unnecessary file access can expose local sensitive data or permit unintended modification of user files, especially when the skill’s purpose does not prepare users to expect filesystem interaction.

Context-Inappropriate Capability

Medium
Confidence
85% confidence
Finding
External API integration is not clearly tied to the manifest’s limited description of chat-style adaptation. Undisclosed network access can enable transmission of user content, preferences, or metadata to third parties, creating privacy and data-governance risks.

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The document claims strong privacy protection, yet elsewhere describes API keys, external connectivity, and messaging/network activity without reconciling how user data is handled. This inconsistency can cause users to underestimate exposure and consent to data flows they do not fully understand.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The invocation guidance is overly broad and ambiguous, spanning marketing, advertising, conversion, and automation contexts without clearly bounding safe use. Such vagueness can lead to overbroad invocation, accidental use in sensitive workflows, and permission grants that exceed the skill’s legitimate needs.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The markdown describes file, API, and command-execution capabilities without prominent upfront warnings about system, privacy, and data-impact implications. Users may invoke the skill expecting harmless chat adaptation while the skill can access files, make network calls, or execute commands.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.