Back to skill

Security audit

Gateway Manager Free

Security checks across malware telemetry and agentic risk

Overview

This skill is mostly an API gateway configuration helper, but its activation metadata also targets unrelated project-management use while granting write and command-execution capability.

Review this before installing. It appears intended for API gateway configuration, not malicious activity, but the activation metadata should be narrowed to gateway-specific tasks and write/exec actions should be explicitly user-directed. Avoid installing it until the project-management trigger text and broad keywords are corrected if your agent auto-activates skills.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest says the skill should be used for project management, task planning, and team collaboration, but the actual content performs API gateway configuration and operational guidance. This domain mismatch can cause the skill to auto-activate in unrelated contexts and unexpectedly request or use read/write/exec capabilities, leading to unsafe execution or incorrect operator trust.

Vague Triggers

High
Confidence
97% confidence
Finding
A vague or mismatched activation description increases the chance the skill will be invoked in unintended situations. Because this skill has read/write/exec tooling, incorrect activation broadens the attack surface and may trigger operational actions when the user expected non-operational assistance.

Vague Triggers

High
Confidence
96% confidence
Finding
The capability coverage keywords are excessively broad and include unrelated productivity and generic automation terms, which can cause over-triggering. In a skill with exec/write access, broad triggers materially raise the risk of accidental invocation, unsafe file generation, or command execution in contexts unrelated to gateway administration.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation instructs the agent to generate deployable configs and run commands, but it does not clearly warn users that write and exec actions may occur. In practice this can lead to silent file creation or command execution, especially when users interpret the skill as advisory rather than operational.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.