Back to skill

Security audit

Cloud Manager Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly cloud-storage guidance, but it asks for broader agent powers and includes risky cloud/file commands without clear safeguards.

Review this skill before installing. It is not clearly malicious, but only use it if you are comfortable with an agent seeing and potentially running cloud-storage commands. Do not let it execute rclone, API, sync, upload, or deletion commands against real files or cloud accounts unless you have checked the paths, understand overwrite/delete behavior, and have a separate backup.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The manifest grants read/write/exec-style capabilities while the skill markets itself as a Markdown-only guidance skill. This mismatch can mislead the agent or user into allowing operational actions beyond the expected advisory scope, increasing the chance of unintended file or command execution.

Intent-Code Divergence

High
Confidence
97% confidence
Finding
The skill explicitly claims to be pure Markdown not requiring exec, yet it both requests exec capability and contains numerous runnable command examples for cloud operations. This discrepancy can lower operator suspicion and enable dangerous command execution, including data sync, copy, overwrite, or deletion-adjacent actions against local and remote storage.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The skill includes operational examples that perform remote cloud synchronization, copying, uploading, and secure deletion-oriented actions. In the context of a consumer guidance skill, these mutations are risky because an agent may apply them to real user data, causing data loss, unintended propagation, or irreversible removal.

Vague Triggers

High
Confidence
89% confidence
Finding
The invocation scope lists broad and mismatched trigger phrases, including project management and team collaboration concepts unrelated to personal cloud-storage guidance. Overbroad activation can cause the skill to be invoked in inappropriate contexts, exposing exec/write capabilities where the user did not intend cloud-management behavior.

Vague Triggers

High
Confidence
90% confidence
Finding
The manifest description instructs using the skill for project management, task planning, progress tracking, and team collaboration, which does not match the stated cloud-storage purpose. This ambiguity increases the chance of accidental invocation in unrelated workflows, where the skill's operational capabilities may be unsafe or confusing.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The shell examples include irreversible actions such as secure deletion after upload without prominent warnings or confirmation requirements. In an agent-executable context, users may treat these as safe defaults and permanently destroy local data if uploads fail, target paths are wrong, or later recovery is needed.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.