Back to skill

Security audit

Google Fonts Tool Free

Security checks across malware telemetry and agentic risk

Overview

This is mostly a Google Fonts guidance skill, but it is under-scoped and asks agents to use it for unrelated writing tasks while advertising vague modify/delete/save capabilities.

Review this skill before installing. It appears intended for Google Fonts advice, but its trigger and capability claims should be narrowed so it only runs for font loading, font pairing, and web-font performance tasks, and any file-changing behavior should be explicitly scoped and user-directed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Intent-Code Divergence

Medium
Confidence
97% confidence
Finding
The trigger-condition section says the skill should be used for marketing copy, title optimization, and content creation, which is unrelated to a Google Fonts loading/pairing tool. This mismatch can cause the agent to invoke the skill in inappropriate contexts, producing irrelevant outputs and potentially steering workflows away from the user's actual intent.

Intent-Code Divergence

Medium
Confidence
94% confidence
Finding
The skill claims generalized create/query/modify/delete and export/save capabilities via input parameters and output configuration, but the rest of the file only documents static guidance about Google Fonts usage. Overstating capabilities can mislead an agent into treating the skill as stateful or file-modifying, increasing the chance of unintended actions or unsafe tool orchestration.

Vague Triggers

High
Confidence
98% confidence
Finding
The trigger condition is overly broad and explicitly mismatched to the skill's stated domain, saying to use it for general writing and marketing tasks. Broad, inaccurate trigger rules are dangerous in agent systems because they increase unintended activation, causing the wrong skill to run and contaminating downstream actions or recommendations.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The documentation advertises modify/reset/import/export/save-style operations without describing what may be changed or requiring user confirmation. In an agent environment with read/exec/write tools enabled, ambiguous change-oriented claims can lead the system to infer permission for data or configuration changes that the user did not explicitly authorize.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.