Back to skill

Security audit

Cloud Manager

Security checks across malware telemetry and agentic risk

Overview

This cloud storage skill asks for powerful account and file-management authority, but its instructions are inconsistent and weakly scoped for automated cleanup and deletion.

Review this skill before installing. Use it only with cloud accounts and folders you are comfortable letting an agent inspect and modify, verify every generated command, and avoid enabling cleanup, deduplication, or scheduled backup rules unless you have backups, narrow paths, dry-run results, and explicit confirmation steps.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The documented output is an unrelated grading/audit schema rather than a cloud-storage management result. This kind of capability confusion can cause an agent to invoke the skill under the wrong assumptions, mishandle sensitive storage actions, or trust fabricated success metadata instead of verifying actual file operations.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The input format asks for generic review fields like content and strict_level instead of concrete cloud-management parameters. This mismatch can lead the agent to accept ambiguous free-form input and translate it into privileged exec-backed operations without clear parameter boundaries or user confirmation.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The dependency section says the skill needs an LLM for intelligent review, which conflicts with its stated purpose as a cloud storage manager. This suggests template contamination or hidden dual use, increasing the risk that an agent routes unrelated review tasks into a skill that also has exec capability and access to cloud credentials.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger text says to use the skill for generic data analysis, reporting, statistics, and visualization, far beyond cloud storage administration. Overbroad invocation guidance can cause the agent to select this exec-capable skill for unrelated tasks, unnecessarily exposing credentials, local files, and command execution pathways.

Missing User Warnings

Medium
Confidence
78% confidence
Finding
The skill advertises version-history comparison and deduplication while elsewhere stating version-history cleanup is physically irreversible, but it does not place a prominent warning near the capability description. In an exec-enabled storage skill, weak safety messaging around irreversible deletion materially increases the chance of accidental data loss.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill promotes scheduled backup and cleanup rules without a prominent warning that cleanup is unattended and may modify or delete data automatically. Because the skill supports exec and cloud targets, unclear guardrails could lead to silent retention mistakes, unintended deletions, or broad propagation of bad rules across providers.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.