Back to skill

Security audit

选配网页字体

Security checks across malware telemetry and agentic risk

Overview

This typography skill is mostly about font advice, but it also asks for broad write, command execution, API, and file-processing authority that is not tightly scoped.

Review this skill before installing. It does not contain an executable payload by itself, but only use it in a workspace where you are comfortable allowing an agent to modify files and run font-related commands. Avoid providing API keys unless the exact service and purpose are clear, and require confirmation before any command execution or file writes.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The skill is presented as a typography advisor, yet it declares read/exec/write and later broader operational capabilities that are not necessary for selecting fonts or generating CSS guidance. This capability mismatch increases the attack surface because a user may authorize powerful actions under the assumption the skill is low-risk and domain-limited.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Advertising command execution for a font-selection skill is unjustified by the core use case and creates a path to run shell commands in environments where the skill is trusted. Even if intended for benign optimization tasks, unnecessary exec access can be repurposed for filesystem changes, data access, or environment inspection.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
The skill claims API integration and information-retrieval abilities unrelated to its typography-focused description, creating capability creep beyond what users would reasonably expect. Such scope expansion can enable unexpected outbound communication or data access, especially when paired with API key configuration guidance.

Intent-Code Divergence

Medium
Confidence
88% confidence
Finding
The statement that risky code and external dependencies were removed conflicts with later sections that describe command execution, API keys, and external communication. This kind of trust-signaling is dangerous because it can lower reviewer suspicion while powerful behaviors remain present, making social engineering or under-review of risky capabilities more likely.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
Declaring write and exec capabilities without prominent user-facing warning or consent language increases the likelihood of unsafe use. In an agent ecosystem, users may invoke the skill for harmless-looking typography advice while unknowingly granting permission for system-impacting operations.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.