Back to skill

Security audit

Code Analysis Skills

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it asks for command execution while its documented purpose and capabilities are inconsistent and under-scoped.

Install only if you are comfortable granting a code-analysis skill local command execution. Use it on repositories you control, avoid providing unnecessary API keys, and require explicit approval before it runs commands or changes files because the artifact does not clearly define those boundaries.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
91% confidence
Finding
The manifest positions the skill as a descriptive Git-history reflection tool, but the body advertises materially broader capabilities such as static analysis, dependency vulnerability detection, upgrade advice, CI/CD integration, and refactoring guidance. This mismatch can mislead users and agents about the skill’s real scope, causing it to be invoked in higher-risk contexts or with broader trust than intended, especially because the skill also declares exec access.

Intent-Code Divergence

Medium
Confidence
78% confidence
Finding
The description claims the skill removes risky code and improves security/stability, but the file only documents reporting and analysis behavior. This creates an unsafe expectation gap: users may rely on the skill for remediation when it merely reports issues, which can lead to unaddressed security problems or incorrect automation assumptions.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill advertises exec capability but does not clearly warn users that commands may be run on the local system or explain the associated risks, limits, or consent model. In an agent setting, undocumented command execution materially increases the chance of unintended system changes, data exposure, or execution against sensitive repositories and environments.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.