Back to skill

Security audit

Cloud Storage Manager Free

Security checks across malware telemetry and agentic risk

Overview

This cloud-storage skill is mostly purpose-aligned, but its activation instructions are mismatched and could route broad project-management requests into a credentialed cloud file-transfer tool.

Review the trigger wording before installing or using this skill. Use it only for explicit cloud-storage tasks, provide least-privilege cloud credentials, avoid putting secrets in shell history or repositories, prefer dry-run or cost-estimation modes before sync/delete/transfer actions, and verify the exact local and remote paths before allowing writes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Low
Confidence
91% confidence
Finding
The trigger condition says to use this skill for project management, task planning, progress tracking, and team collaboration, which is unrelated to cloud storage operations. Overbroad and mismatched routing criteria can cause the agent to invoke a filesystem/network-capable skill in inappropriate contexts, increasing the chance of unintended data access, file modification, or credential use.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger description is both overly broad and semantically inconsistent with the skill's purpose, making accidental invocation likely. Because this skill has read/write/exec capabilities and can operate on local and remote storage, mis-triggering could lead to destructive syncs, credential exposure through command execution, or unintended transfers to third-party cloud providers.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill instructs users to configure provider credentials and persist them locally, but it does not prominently warn about sensitive-secret handling risks, local compromise, shell history leakage, or least-privilege requirements at the point of use. In a skill with exec support and access to multiple cloud providers, weak credential hygiene can directly enable account takeover or unauthorized cloud data operations.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The documentation describes upload, download, sync, export, save, and conversion behaviors without a clear consolidated warning that these actions may modify local files or remote cloud data. In the context of a storage-management skill with write and exec permissions, insufficient disclosure increases the risk of users or upstream agents invoking destructive or privacy-impacting operations without informed consent.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.