Back to skill

Security audit

上市策略

Security checks across malware telemetry and agentic risk

Overview

This GTM planning skill is mostly advisory, but it asks for broad read/write/command authority and describes API, file, and command operations that are not clearly scoped to its business-strategy purpose.

Review this skill before installing. It does not show malicious code or exfiltration, but it asks an agent for powers that are broader than needed for GTM advice. Only use it in an environment where command execution and file writes are restricted or require explicit approval, and avoid providing API keys or sensitive business files unless the workflow is clearly narrowed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (6)

Intent-Code Divergence

Medium
Confidence
92% confidence
Finding
The skill is presented at the end as a pure Markdown/natural-language skill, yet elsewhere advertises write, exec, and API-driven behavior. This inconsistency can mislead users and host agents about the actual trust boundary and may cause an agent to grant or exercise unnecessary powerful capabilities under the guise of a harmless GTM planning guide.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
Claiming commands run in a 'secure sandbox' without any actual sandbox design, boundaries, or enforcement details creates a false sense of safety. Users or agents may permit execution they otherwise would block, assuming containment exists when the skill itself provides no such guarantee.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill requests exec capability even though its stated purpose is GTM strategy generation, which is primarily advisory and text-based. Unnecessary execution privileges increase attack surface and create opportunity for misuse if the skill is triggered in broader automation contexts.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Advertising broad file processing and external API integration for a GTM strategy skill expands expectations far beyond the business-planning use case. This can normalize high-risk actions and lead agents or users to expose files, credentials, or network access unnecessarily.

Vague Triggers

High
Confidence
93% confidence
Finding
The activation language is extremely broad, describing generic productivity, automation, batch processing, and workflow optimization scenarios rather than a narrowly scoped GTM task. Overbroad invocation criteria increase the chance the skill will be selected in unrelated contexts where its declared powerful tools could be abused.

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The document describes writing files, calling APIs, and executing commands without prominent upfront warnings, consent requirements, or impact disclosure. That omission increases the risk of silent system-affecting behavior, especially if an agent maps these descriptions into real tool usage.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.