Back to skill

Security audit

documentation-and-ad

Security checks across malware telemetry and agentic risk

Overview

The skill is a vague documentation/ADR helper that requests broad command-execution and credential/API workflows without tight scoping or user controls.

Install only if you are comfortable granting a documentation-branded skill broad local command and file-reading authority. Prefer using it with explicit prompts for ADR/documentation work only, avoid providing API keys unless clearly necessary, and require confirmation before any command execution or file-changing action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill is presented as an ADR/documentation helper, but its declared tools and guidance broaden into generic automation, API use, file handling, and command execution. This scope mismatch can cause an agent or user to grant broader privileges than necessary, increasing the chance of misuse or unsafe execution paths unrelated to documentation.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Exposing exec capability for a documentation/ADR skill is unnecessary and materially expands the attack surface. If the skill is invoked on untrusted content or with permissive prompting, command execution could enable arbitrary local actions, data access, or chaining into more serious compromise.

Context-Inappropriate Capability

Medium
Confidence
88% confidence
Finding
The skill normalizes API keys, external connectivity, and GitHub-derived data sources without clearly tying them to the ADR/documentation function. This can lead operators to provide network and credential access that is broader than needed, creating avoidable exposure of secrets and outbound data flows.

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The document markets the skill as decision-recording/documentation, while other sections describe a generic automation and command-execution utility. This inconsistency is dangerous because users may trust and enable the skill under a low-risk mental model while it actually operates with substantially broader capabilities.

Vague Triggers

Medium
Confidence
83% confidence
Finding
An overly broad trigger such as activating whenever a user needs 'related operations' creates excessive and ambiguous invocation scope. In practice this can cause the skill to run in contexts not intended by the user, increasing the chance of unnecessary tool use, data access, or execution of unsafe actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.