Back to skill

Security audit

Creative Officer

Security checks across malware telemetry and agentic risk

Overview

The skill mostly provides marketing and brand-planning guidance, but it asks for shell command access that its own instructions say is not needed.

Review before installing. The content functions look purpose-aligned, but the requested shell access is broader than needed for brand strategy and creative planning. Prefer installing only if exec is removed or tightly scoped, or if you are comfortable granting command execution to this skill.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill claims its core functionality is pure Markdown and does not require exec, yet it declares exec in the manifest and repeatedly instructs users to run shell/network diagnostic commands such as ping. This mismatch weakens trust boundaries because operators may grant unnecessary command execution privileges to a skill whose documented business purpose is creative planning, increasing the chance of unsafe command use or privilege abuse.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
This skill is presented as a brand-management and creative strategy assistant, but it requests shell execution capability without a justified functional requirement. Unnecessary exec access violates least-privilege principles and creates an avoidable avenue for command execution, environment inspection, or follow-on abuse if the skill is ever prompted into operational behavior.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.