Back to skill

Security audit

防火墙

Security checks across malware telemetry and agentic risk

Overview

This firewall skill does not show malware behavior, but it asks for command and write authority for high-impact firewall changes without enough scoping or rollback guidance.

Review before installing. Use this only for audit or tightly supervised firewall work unless the publisher adds explicit dry-run behavior, confirmation prompts, exact rule scope, backup and rollback steps, and platform-specific safety checks.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
95% confidence
Finding
The documented output schema is unrelated to firewall configuration and instead describes a generic code-style/security scoring report. In a security automation skill, this mismatch can cause users or agents to mis-handle results, trust that firewall changes were applied when they were not, or make unsafe follow-up decisions based on fabricated or ambiguous output semantics.

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The skill is described in one place as pure Markdown/natural-language driven, while elsewhere it declares exec capability and command execution behavior. This inconsistency obscures the real execution model and may lead users to approve or invoke the skill without understanding that it can run system commands affecting firewall state.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill advertises automated firewall configuration plus command execution but does not prominently warn about service disruption, lockout, or network outage risks from incorrect rule changes. In firewall management, silent or underemphasized execution risk is dangerous because a single mistaken command can cut off SSH, expose services, or interrupt production traffic.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.