Back to skill

Security audit

deprecation-and-migr

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it asks for broad read and command execution authority while its actual instructions are much broader than its deprecation-and-migration name suggests.

Review before installing. Use this only if you are comfortable granting an agent broad read and command execution capability for loosely defined automation tasks; do not use it for sensitive repositories, credentials, or production migration work unless the publisher narrows the scope and documents command, file, and credential safeguards.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The skill is advertised as a deprecation/migration capability, but the body describes generic automation, API usage, file handling, and command execution. This mismatch can mislead an agent or user into invoking a much broader operational capability than expected, increasing the chance of unsafe execution under a trusted, narrow-seeming label.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Declaring exec for a skill framed as deprecation/migration unnecessarily expands the attack surface, especially when the documentation also normalizes command execution. In an agent ecosystem, shell execution can be abused for unintended local actions, data access, or lateral workflow impact if the skill is invoked based on its misleadingly narrow purpose.

Intent-Code Divergence

Medium
Confidence
93% confidence
Finding
The substantive feature list describes a generic data-processing and automation tool rather than a migration-specific skill. This deceptive or sloppy scoping makes the skill more dangerous because users and orchestrators may grant trust, permissions, or automatic routing based on the stated purpose while the actual functionality is broader.

Vague Triggers

High
Confidence
89% confidence
Finding
The trigger condition says the skill should activate whenever a user needs to perform 'related operations,' which is overly broad and ambiguous. In combination with generic automation language and exec capability, this can cause inappropriate or automatic invocation for tasks outside the user’s intent, leading to unsafe actions or overbroad data/command handling.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill references API keys, file operations, and command execution, but does not provide clear front-and-center warnings that these actions may access credentials, modify files, or run system commands. This omission increases the risk of users or agents invoking impactful behavior without informed consent or adequate safeguards.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.