Back to skill

Security audit

DNS查询专业版

Security checks across malware telemetry and agentic risk

Overview

This DNS monitoring skill appears legitimate, but its activation scope is too broad for a skill that can run commands, write files, keep history, and send alerts.

Review before installing. Use this skill only for DNS diagnostics and monitoring, and require explicit approval before it writes reports, creates scheduled monitoring, stores history, or sends webhook/email notifications. Do not allow it to handle unrelated deployment, log-analysis, or general automation tasks without a separate review.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Vague Triggers

High
Confidence
93% confidence
Finding
The skill description uses very broad activation language such as using it for monitoring, log analysis, alerting, and deployment management, which extends far beyond DNS lookup. In an agent ecosystem, overly broad scope can cause the skill to be invoked for unrelated tasks while it exposes read, write, and exec capabilities, increasing the chance of unintended command execution or data handling.

Vague Triggers

High
Confidence
95% confidence
Finding
The dedicated trigger section says to use the skill whenever efficiency, automation, batch processing, or workflow optimization is needed, which is so vague that it can match many unrelated requests. Because the skill advertises exec, write, and external notification behaviors, ambiguous activation criteria raise the risk of accidental overreach and misuse in contexts the user did not intend.

Missing User Warnings

Medium
Confidence
90% confidence
Finding
The skill documents command execution, local file reads/writes, persistent history storage, and webhook/email notifications, but it does not clearly surface these as material side effects near the usage/trigger flow. That can lead users or orchestration systems to invoke it without realizing data may be persisted locally or transmitted to external endpoints.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.