Back to skill

Security audit

Csv Insight Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a CSV analysis helper that asks for local read/execute/write capabilities in ways that match its stated CSV statistics and export purpose, with some documentation quality gaps users should notice.

Install only if you want an agent to analyze local CSV files and possibly create exported CSV results. Review the exact command and output path before running it, especially because the artifact does not include the referenced script and does not explain overwrite behavior.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Vague Triggers

Medium
Confidence
80% confidence
Finding
The skill description is broad enough to match many generic data-analysis requests, which can cause the agent to over-select this skill and invoke read/write/exec capabilities more often than necessary. In this context, overbroad routing increases risk because the skill advertises command execution and file output, so accidental activation could lead to unnecessary local command runs or unintended file handling.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill encourages command execution and writing output files but does not clearly warn that local commands may run and files may be created or overwritten. In an agent environment with read/write/exec tools, this omission can cause users to authorize actions without understanding their side effects, increasing the chance of unintended filesystem changes or risky command use.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.