Back to skill

Security audit

data-analysis-toolkit

Security checks across malware telemetry and agentic risk

Overview

This data-analysis skill is not malicious, but it asks for broad execution and integration authority that is not tightly scoped or clearly consented to.

Review before installing. Use this skill only when you are comfortable with an analysis helper that may write files and run commands, and avoid providing sensitive datasets unless you can ensure no external API or callback behavior is used without explicit approval.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The skill is presented as a data-analysis assistant, but its documented capabilities expand to file writing, external API integration, and system command execution. This creates a scope mismatch that can cause an agent or user to invoke a seemingly low-risk analytics skill that actually has materially higher side effects and attack surface.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
External API integration is advertised even though the skill’s stated purpose is local data cleaning, statistics, and visualization guidance. Unnecessary outbound connectivity increases the risk of unintended data exfiltration, especially if users provide sensitive business or research datasets for analysis.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Documenting system command execution for a general data-analysis skill is dangerous because it enables actions far beyond analysis, including arbitrary local operations, environment inspection, and chaining with file read/write. In this context, the broad analytics invocation language makes misuse more likely because ordinary analysis requests could route to a skill with unnecessary execution authority.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The invocation wording is broad enough to match common requests for analysis, reporting, and visualization, which increases the chance this skill is selected in routine workflows. Because the skill also declares write/exec capabilities, overbroad routing materially raises the risk of unnecessary exposure to powerful tools.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill advertises file writing, external API use, and command execution without prominent user-facing warnings or consent boundaries. Users may reasonably expect a passive analysis helper, but these capabilities can alter local state or transmit data externally, creating hidden side effects and trust violations.

VirusTotal

60/60 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.