Back to skill

Security audit

自适应设计偏好引擎

Security checks across malware telemetry and agentic risk

Overview

This skill mainly fits a design-preference assistant, but it asks for broad file, API, command, and persistent profiling behavior without enough scope or user control.

Review before installing. Use it only if you want an agent to build a long-lived design preference profile, and avoid granting exec, API keys, callback URLs, or broad filesystem access unless the publisher narrows those capabilities and provides clear controls to inspect, edit, and delete the archive.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Intent-Code Divergence

High
Confidence
94% confidence
Finding
The skill’s stated scope excludes design-tool control and rendering, but the document later advertises file processing, API integration, and command execution. That scope expansion is dangerous because it can justify broader agent privileges than users expect, increasing the chance of unintended filesystem, network, or shell actions under a benign design-oriented label.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Advertising shell command execution is unjustified for a design-preference learning skill and materially increases risk. If an agent is allowed to invoke `exec` based on this documentation, prompt-influenced or malformed inputs could trigger arbitrary local command execution, affecting system integrity and confidentiality.

Context-Inappropriate Capability

Medium
Confidence
87% confidence
Finding
External API integration is not clearly necessary for locally learning and applying user design preferences. Unnecessary network access broadens the attack surface and creates data-exfiltration risk, especially because the skill also describes collecting persistent preference signals from user interactions.

Description-Behavior Mismatch

High
Confidence
95% confidence
Finding
The skill drifts from a narrow preference-learning assistant into a generic automation tool that can read/write files, call APIs, and run commands. This mismatch is dangerous because users and host platforms may grant trust based on the narrow branding, while the actual behavior supports far more powerful and potentially abusable operations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill says it will observe user choices and feedback to build preferences, but it does not clearly disclose that those interaction signals are persisted into an archive. Silent retention of behavioral data is risky because users may reveal sensitive preferences, brand information, or work patterns without informed consent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
Automatically confirming and writing preferences after two matching signals creates persistent profiling without an explicit confirmation step. This can encode inaccurate, sensitive, or context-specific inferences into a long-lived profile and may influence future outputs in ways the user did not knowingly authorize.

Ssd 3

Medium
Confidence
92% confidence
Finding
The skill explicitly describes persistent collection and retention of user preference signals to build an evolving profile. Persistent behavioral profiling is dangerous when retention boundaries, access controls, and consent mechanisms are unclear, because it can expose sensitive user tendencies, client preferences, or proprietary brand patterns.

Ssd 3

Medium
Confidence
94% confidence
Finding
The skill directs extraction of signals from user behavior, feedback, modifications, and emotional reactions for storage, which amounts to systematic profiling. Inferring preferences from emotional reactions is especially sensitive and can capture more personal information than users expect from a design helper.

Ssd 3

Medium
Confidence
93% confidence
Finding
The operational workflow instructs the agent to observe interactions and write repeated signals into a persistent archive, making the profiling behavior an active part of normal operation. Without explicit approval and strong storage safeguards, this creates a privacy and data-governance risk disproportionate to the stated design-assistance function.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.