Back to skill

Security audit

仪表盘分析工具

Security checks across malware telemetry and agentic risk

Overview

The skill does not show clear malicious behavior, but it asks for broad file, command, and API authority while giving inconsistent limits and data-retention statements.

Install only if you are comfortable with an analytics skill that may read and write files, execute commands, call external APIs, and use an API key. Keep it limited to trusted workspaces and non-sensitive data until the publisher clarifies supported real-time behavior, command/write confirmation, CRUD scope, and log/data retention.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill metadata says it is not suitable for real-time stream processing, but the body advertises real-time monitoring and streaming capabilities. This inconsistency can cause an agent or user to rely on the skill in unsupported contexts, creating unsafe operational assumptions, overload, or misuse of external APIs and local tooling.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document claims user data is not retained, yet elsewhere says operation results, errors, and audit logs are recorded. Contradictory data-handling promises can lead users or agents to expose sensitive inputs under false privacy assumptions, increasing the risk of inadvertent retention and compliance violations.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The FAQ states the tool is not appropriate for real-time data streams, while other sections describe real-time monitoring and streaming processing as supported features. This conflicting guidance can trigger unsafe deployment decisions and cause agents to invoke the skill for workloads it may not safely handle.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The activation scope is extremely broad for generic analytics, reporting, statistics, and visualization scenarios. Because the skill also exposes read, write, and exec tools, over-broad triggering increases the chance of unnecessary command execution, file modification, or external API actions in contexts where a narrower tool would be safer.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill exposes powerful read, write, and exec capabilities but does not clearly warn users that it may execute commands or modify local files. In an agent setting, this lack of disclosure undermines informed consent and can lead to risky side effects from seemingly routine analytics prompts.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.