Back to skill

Security audit

Data Analysis Hub Free

Security checks across malware telemetry and agentic risk

Overview

The skill appears to be a legitimate data-analysis helper, but it asks for broad command and file-writing authority without clear limits.

Install only if you are comfortable letting the skill read local data files and potentially run Python or shell commands for analysis. Keep it to non-sensitive datasets unless you can review each command and file write, and avoid providing production credentials or unrestricted environment secrets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is described as a methodology-focused analytics assistant, but its manifest exposes broader capabilities such as file writing and command execution that are not necessary for the stated free-edition purpose. This capability mismatch increases the attack surface because a user invoking a benign analysis workflow could unintentionally grant the skill authority to modify files or run commands.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Arbitrary command execution is a powerful capability that is not clearly justified for a statistics and decision-support skill, especially one marketed as a lightweight free assistant. If the agent follows natural-language prompts to analyze local files or data sources, exec could be abused to run shell commands, inspect the environment, or pivot into broader system actions.

Context-Inappropriate Capability

Low
Confidence
84% confidence
Finding
File write access is broader than what is needed for a tool that primarily provides analysis guidance and structured conclusions. Even without overtly malicious logic in the markdown, write capability can be abused to alter local project files, overwrite reports, or plant misleading artifacts during an otherwise normal analysis session.

Vague Triggers

Medium
Confidence
77% confidence
Finding
The trigger conditions are so broad ('use when data analysis, report generation, statistical insights, data visualization are needed') that the skill may activate for many common requests beyond its narrow methodology purpose. In the presence of privileged tools like exec and write, over-triggering materially increases the chance that dangerous capabilities are invoked in inappropriate contexts.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.