Back to skill

Security audit

Doc Guard Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly an encrypted document tool, but it is scoped too broadly and may expose document decryption links by default.

Install only if you intend to use it for encrypted Markdown document workflows through a trusted MCP server. Do not rely on it for general SQL or database tasks, confirm before deletion, and treat any full share URL containing the # encryption key fragment like a password because anyone with the complete link can decrypt the document.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as an end-to-end encrypted document tool, but its 'Use when' guidance broadly redirects agents toward generic database, SQL, and storage tasks outside the stated capability. That mismatch can cause inappropriate invocation in unrelated data-management contexts, potentially exposing sensitive data to the wrong tool path or causing unsafe automated actions under false assumptions about encryption and scope.

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as an end-to-end encrypted document tool, but its 'Use when' guidance broadly redirects agents toward generic database, SQL, and storage tasks outside the stated capability. That mismatch can cause inappropriate invocation in unrelated data-management contexts, potentially exposing sensitive data to the wrong tool path or causing unsafe automated actions under false assumptions about encryption and scope.

Vague Triggers

High
Confidence
94% confidence
Finding
Overly broad invocation guidance is dangerous in an agent skill because it increases the chance that the skill is auto-selected for tasks it was not designed to handle. In this context, the mismatch between encrypted markdown collaboration and generic SQL/data-storage wording could trigger unintended read/write/exec actions, expanding the blast radius of mistakes and undermining user expectations about what data is being processed.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
Presenting deletion as a standard capability without an immediate irreversibility warning increases the risk of accidental destructive actions, especially in agent-driven workflows where tools may execute quickly. Because the skill includes write/exec capabilities and document deletion is explicitly '不可恢复,' delayed warning text is insufficient to protect users from unintended data loss.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation encourages always returning full share links that include the encryption key fragment in the URL hash, but does not warn that this fragment is effectively sensitive secret material. In an agent setting, such links may be echoed into chat history, logs, telemetry, screenshots, or copied into less-trusted channels, which would defeat the confidentiality guarantees of the encrypted document.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.