Back to skill

Security audit

Html Toolkit Free

Security checks across malware telemetry and agentic risk

Overview

This appears to be an HTML checklist skill, but it requests broad read/write/exec authority and has unrelated communication triggers that could invoke it outside its stated purpose.

Review this carefully before installing. It is not clearly malicious and contains no executable payload, but its permissions and trigger wording are broader than an HTML self-check skill needs. Prefer a version that limits triggers to HTML/accessibility/SEO review and explicitly scopes any file edits or shell commands.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Intent-Code Divergence

Medium
Confidence
84% confidence
Finding
The skill is presented as an HTML self-check tool, but its trigger conditions mention messaging, notifications, email, SMS, and communication integration. This mismatch can cause an agent to invoke the skill in unrelated contexts, potentially exposing read/write/exec capabilities outside the intended HTML-audit scope and increasing the chance of unsafe actions under false pretenses.

Vague Triggers

Medium
Confidence
90% confidence
Finding
An overly broad trigger condition increases the likelihood that the skill will be selected for tasks unrelated to its stated purpose. Because the skill declares read, write, and exec tools, mistaken invocation can expand the operational footprint and lead to unintended file changes or command execution in contexts where the user did not expect such behavior.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill advertises create/modify/delete/save/export style operations and includes exec capability, but it does not warn users that running it may alter files or invoke commands. In an agent setting, that omission is dangerous because users may treat the skill as a passive checker when it may instead perform state-changing actions on the filesystem or shell.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.