Back to skill

Security audit

创意总监专业版

Security checks across malware telemetry and agentic risk

Overview

This skill appears to be a marketing and branding assistant, but its routing text advertises generic software-development use while declaring broad file and shell tools.

Review this before installing. It does not show destructive or exfiltration behavior, but its metadata should be corrected to creative and branding tasks only, and its tool permissions should be narrowed unless a concrete workflow truly needs file mutation or shell access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest description advertises the skill for code generation, debugging, testing, and deployment, while the body implements a branding/marketing creative-director workflow. This mismatch can cause inappropriate auto-selection in developer contexts, leading an agent to invoke an unrelated high-privilege skill with Read/Write/Edit/Bash permissions under false pretenses.

Intent-Code Divergence

High
Confidence
96% confidence
Finding
The documentation explicitly claims the listed capabilities cover the declared usage scenarios, but they still do not match the manifest's developer-tool framing. This reinforces deceptive routing metadata and can mislead humans or orchestration systems into trusting the skill for software-engineering tasks it does not perform.

Vague Triggers

Medium
Confidence
87% confidence
Finding
The activation text is broad enough to overlap with common development requests such as programming assistance, debugging, testing, and deployment. In an agent ecosystem, overly broad routing language can cause this skill to be invoked outside its intended domain, increasing the chance of unsafe file or shell access because the skill declares powerful tools.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.