Back to skill

Security audit

Content Filter Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is a content-filtering instruction file, but it asks for command execution, file writes, network feed access, token use, and an unrelated marketing trigger without clear limits.

Review before installing. Use only if you are comfortable with an agent writing local rule files, running shell commands, contacting feed endpoints, and using a feed-service token. The marketing trigger and required LLM API should be corrected or constrained before routine use.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
88% confidence
Finding
The skill markets itself as a personal/local content filter, but its documentation expands scope to pulling remote feeds and using service authentication. This mismatch can mislead users and agents into granting network access and handling tokens for behavior they would not expect from a local-only filtering tool, increasing the risk of over-privileged execution and unintended data exposure.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The documented free-version feature set only needs deterministic keyword/regex and author filtering, yet it declares an LLM API as required. An unnecessary LLM dependency expands the trust boundary, may transmit feed content or rules to external services, and creates hidden privacy and cost risks without clear functional justification.

Intent-Code Divergence

Medium
Confidence
82% confidence
Finding
The documentation labels content viewing as read-only, but elsewhere describes saving/exporting and hard-deletion behavior. This inconsistency can cause users or agents to assume a non-destructive mode while the skill performs state-changing actions, leading to accidental data loss or unsafe automation decisions.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger condition says to use the skill for marketing promotion, ad placement, customer acquisition, and growth tasks, which is inconsistent with a personal anti-noise content filter. Overbroad and mismatched triggers can cause agents to invoke this skill in unrelated contexts, potentially executing commands, modifying local files, or accessing networks when the user did not intend to use a filtering tool.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill can write local rule files, execute shell commands, and access network services, but it lacks a single clear warning describing these risks. Without explicit notice and consent boundaries, users may unknowingly allow file modification, token use, and outbound connections, which raises the likelihood of privacy issues and unsafe execution.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.