Back to skill

Security audit

claude-api

Security checks across malware telemetry and agentic risk

Overview

The skill is not clearly malicious, but it asks for command execution while describing a vague API/reference automation role that is not tightly scoped.

Review this before installing. It does not contain obvious malware or executable payloads, but it grants command execution for a broad and vaguely described automation/reference skill. Only use it if you specifically want that authority, and avoid providing credentials or allowing shell commands unless the requested action is explicit and understood.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
90% confidence
Finding
The skill is presented as a documentation/reference aid, but the body expands its scope into active automation, command execution, file handling, retries, and batch processing. This mismatch can mislead an agent into granting the skill broader trust and invoking operational behavior where only passive reference behavior was expected, increasing the chance of unintended execution or over-privileged use.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Including the exec capability in a skill whose stated purpose is API reference/documentation violates least privilege and creates unnecessary attack surface. Even without embedded exploit code, an agent may be induced to execute shell commands under the pretense of using a harmless reference skill, enabling unintended system interaction.

Intent-Code Divergence

Medium
Confidence
89% confidence
Finding
The file instructs the agent to read the skill as a pre-open reference, but later describes active processing, command execution, and runtime behavior. This inconsistency is dangerous because it obscures the real trust boundary: a skill that appears informational may actually influence or justify actions on files, commands, or external systems.

Vague Triggers

Medium
Confidence
78% confidence
Finding
The trigger condition is broad enough to match general development, automation, data analysis, and orchestration scenarios, which can cause the skill to be invoked far outside its narrow intended context. Over-broad routing increases the risk that agents apply this skill in inappropriate situations and inherit its confusing execution-oriented guidance.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.