Back to skill

Security audit

Csv Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This CSV guide is mostly ordinary reference material, but it requests broad write and command execution capability and includes unrelated security trigger language without clear limits.

Review this skill before installing. It appears to be a CSV reference guide rather than malware, but it should be limited to CSV parsing/generation tasks and ideally should not have broad exec permission or unrelated security-scan triggers unless the publisher documents exact safe workflows and user confirmations.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a Markdown reference guide, but its documented behaviors expand into operational create/modify/export/save workflows. That mismatch can mislead users or agents into performing file-affecting actions under the guise of passive guidance, reducing informed consent and weakening safety controls around write-capable behavior.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The skill declares exec capability even though its stated purpose is CSV guidance and best-practice reference. Unnecessary command-execution scope increases attack surface substantially: an agent may be induced to run shell commands unrelated to CSV advice, especially when the documentation also implies actionable workflows.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The skill says it is not suitable for unauthorized security work, yet its trigger conditions explicitly include security detection, compliance audit, vulnerability scanning, and encryption protection. This contradiction broadens the skill’s perceived scope into security operations it is not designed for, increasing the chance an agent misapplies it in sensitive contexts.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger conditions are unrelated to the CSV domain and are overly broad, explicitly invoking security detection, compliance audit, vulnerability scanning, and encryption protection. In a skill with read/write/exec tooling, ambiguous activation criteria can cause unsafe invocation in high-risk contexts, leading agents to over-trust the skill’s authority and capabilities.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The markdown describes create/modify/export/save operations without warning users that the skill also has write and exec capabilities. In practice, this can normalize state-changing actions and cause users or agents to authorize file modifications or command execution without clear notice, which is especially risky given the mismatch with the claimed reference-guide nature of the skill.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.