Back to skill

Security audit

Dns Config Tool Free

Security checks across malware telemetry and agentic risk

Overview

The DNS guidance itself is ordinary, but the skill’s activation rule is too broad for a DNS-only tool and could apply it to unrelated coding or deployment work.

Review the trigger wording before installing. The DNS instructions are generally purpose-aligned, but the skill should only activate for DNS record checks, TTL planning, mail authentication, propagation verification, and apex/www troubleshooting; unrelated coding, debugging, or deployment work should not use it.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
94% confidence
Finding
The trigger condition says the skill should be used for broad scenarios like code generation, programming assistance, debugging, and deployment, which far exceeds a DNS configuration skill's intended purpose. In an agentic environment, overly broad routing criteria can cause the wrong skill to activate and gain access to exec-backed actions in contexts where DNS tooling is irrelevant, increasing the chance of unintended command execution or unsafe task handling.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.