Back to skill

Security audit

Cloud Free

Security checks across malware telemetry and agentic risk

Overview

This cloud-storage advice skill is mostly informational, but it asks for shell execution and API-key setup that do not fit its stated purpose.

Review this skill before installing. Its advice content is ordinary, but a user should remove or constrain exec and ignore the generic API_KEY setup unless the publisher explains a specific, user-approved command workflow.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill declares the `exec` tool even though its stated purpose is purely advisory: recommending consumer cloud-storage services and clarifying concepts. Unnecessary shell execution expands the attack surface and could let future prompts, tool-routing mistakes, or prompt-injection content trigger command execution in a context where no execution is needed.

Vague Triggers

Medium
Confidence
83% confidence
Finding
The trigger phrases are broad generic terms like cloud storage and backup-related wording that could match ordinary conversation unintentionally. Over-broad activation can cause the wrong skill to engage, increasing the chance of irrelevant guidance, unneeded tool access, or interaction with an overprivileged skill configuration such as the declared `exec` capability.

Vague Triggers

Medium
Confidence
81% confidence
Finding
The repeated invocation language uses placeholders like '按照skill规范执行' and generic input/output boilerplate without defining exact activation boundaries or permissible actions. Ambiguous orchestration text can lead an agent framework to over-apply the skill or infer behavior beyond its intended advisory scope, especially risky when the skill also declares shell execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.