Back to skill

Security audit

Flow Manager Pro Free

Security checks across malware telemetry and agentic risk

Overview

This skill is not malicious, but it gives an agent command-line authority to change live Node-RED instances and its safety boundaries are not clear enough.

Review this carefully before installing. Use it only for intended Node-RED instances, prefer test environments first, keep credentials scoped, back up flows before deploy/delete/remove operations, and do not rely on the documented restore example unless the actual CLI proves that recovery path exists.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
94% confidence
Finding
The skill documentation is internally inconsistent about whether restore, context access, and environment-related data handling are available in the free edition. In a skill that can execute administrative Node-RED operations, this mismatch can mislead users and agents into attempting unsupported or higher-risk state-changing actions without understanding the true capability and blast radius.

Intent-Code Divergence

Medium
Confidence
96% confidence
Finding
The document states that rollback and full restore are not supported, yet earlier provides a restore command in a CI rollback scenario. This contradiction is dangerous because operators or agents may rely on a non-existent recovery path before performing destructive deployments, increasing the chance of unrecoverable outages or configuration loss.

Vague Triggers

Medium
Confidence
86% confidence
Finding
The scope language is overly broad and includes generic coding, debugging, testing, and deployment triggers beyond narrow Node-RED administration. In agent ecosystems, broad activation criteria can cause this exec-capable skill to be selected in unrelated contexts, increasing the chance of unnecessary command execution against administrative endpoints or local tooling.

Missing User Warnings

Medium
Confidence
97% confidence
Finding
The skill exposes destructive administrative actions such as deploy, delete-flow, remove-node, and set-context without prominently warning about service interruption, overwrites, privilege requirements, or rollback preparation. Given that the skill is intended for command execution against live Node-RED instances, omission of these safeguards materially raises the risk of accidental production disruption or loss of configuration/state.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.