Back to skill

Security audit

图解

Security checks across malware telemetry and agentic risk

Overview

This diagram skill needs review because it asks for broad file and command authority while its instructions stray beyond diagram generation.

Install only if you are comfortable reviewing when the agent may read or write files or run commands. Prefer using it for explicit diagram requests, and avoid granting shell or broad filesystem access unless a specific rendering or export step requires it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a diagram generator, but later claims generic file handling, API integration, and command execution capabilities that substantially broaden its effective authority. This mismatch can cause an agent or user to invoke the skill in situations they would not have approved, increasing the chance of unnecessary file access or shell execution under a misleading label.

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documented output format is a grading/evaluation JSON structure rather than diagram content, which contradicts the stated purpose of generating Mermaid/PlantUML/ASCII diagrams. Such schema confusion can mislead downstream automation into treating the skill as an evaluator or accepting unexpected output types, weakening validation and enabling unsafe workflow composition.

Vague Triggers

Medium
Confidence
79% confidence
Finding
Overly broad activation conditions make the skill eligible for many loosely related scenarios such as project management, planning, tracking, and collaboration, beyond narrowly defined diagram generation. In an agentic environment, this can cause over-selection of a tool with read/write/exec permissions, unnecessarily expanding exposure to sensitive context and privileged actions.

Natural-Language Policy Violations

Medium
Confidence
76% confidence
Finding
The description states support for Chinese interaction in a way that can bias or force language behavior without clear user opt-in. While not a severe security issue by itself, unexpected language switching can degrade user comprehension of prompts, outputs, and safety notices, making misuse or approval errors more likely in sensitive workflows.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.