Back to skill

Security audit

db-free

Security checks across malware telemetry and agentic risk

Overview

This skill does not show clear malicious behavior, but it asks for broad read, write, and command execution authority while describing capabilities beyond its database-help purpose.

Review this skill before installing. It may be useful for database troubleshooting, but only grant read, write, or command execution access when you intend to let it inspect files, modify files, or run commands, and prefer limiting use to explicit database-related tasks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

High
Confidence
94% confidence
Finding
The skill is presented as a narrow database pitfall advisory tool, but later documentation expands it into generic file processing, API integration, and command execution. This capability mismatch can mislead users and host agents into granting broader permissions than are necessary, increasing the chance of unsafe execution, filesystem modification, or unintended external calls under the guise of a benign database helper.

Vague Triggers

Medium
Confidence
90% confidence
Finding
The trigger condition activates on generic 'Development' tasks, which is much broader than the database-focused purpose of the skill. Overbroad auto-activation increases the chance the skill will be invoked in unrelated contexts where its read/write/exec capabilities and generic automation guidance could influence actions unexpectedly or unsafely.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation advertises write, exec, and API capabilities but does not prominently warn about the risks of modifying files, running system commands, or calling external services. In an agent setting, this omission can cause users or orchestrators to treat the skill as low-risk guidance while it may actually perform impactful actions, leading to accidental changes, data exposure, or misuse of credentials.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.