Back to skill

Security audit

图表工具专业版

Security checks across malware telemetry and agentic risk

Overview

This diagram skill is not clearly malicious, but it asks agents to use broad file, command, API, and credential-related capabilities beyond a narrowly scoped diagram tool.

Install only if you are comfortable with a diagram skill that may prompt your agent to run local commands, search/read files, call external APIs, and write exported files. Use it with explicit output paths and review any generated commands, webhook URLs, credential handling, and batch operations before execution.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The skill is presented as a diagram tool, but the later capability list expands to generic file handling, API integration, command execution, and information retrieval. This scope inflation is dangerous because a user or agent may invoke powerful local and network actions under a deceptively narrow, low-risk description, increasing the chance of unintended file/system operations.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The invocation guidance says to use the skill for broad data analysis, report generation, statistical insight, and visualization tasks, which goes well beyond a narrowly scoped diagram helper. Overbroad triggers can cause an agent to select this skill in unrelated contexts where its exec, read, grep, glob, and integration capabilities may be unnecessarily exposed.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The documentation advertises export, batch rendering, and version-management style operations that imply local file creation or modification, but it does not prominently warn users that local files may be written or overwritten. In an agent context, this can lead to silent filesystem changes, accidental overwrites, or unsafe assumptions about read-only behavior.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.