Back to skill

Security audit

idea-refine

Security checks across malware telemetry and agentic risk

Overview

This skill is not clearly malicious, but it asks for broad command and data-processing authority that does not fit its stated idea-refinement purpose.

Install only if you intend to give this skill broad local read access and possible shell/API workflow authority. Before use, require explicit confirmation for every command, file operation, API call, and credential use, and avoid providing real secrets until the publisher narrows the scope and documents data flows clearly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The skill is presented as an idea-refinement assistant, but its documentation expands into broad automation, data processing, API access, file handling, and command execution. This mismatch can cause an agent or user to authorize capabilities far beyond the expected scope, increasing the risk of unintended code execution, data access, or external communications under an innocuous label.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Granting exec capability to a skill whose stated purpose is refining ideas is unjustified and materially increases attack surface. If invoked by an agent, this could enable shell command execution unrelated to brainstorming, leading to filesystem changes, data exfiltration, or execution of untrusted commands.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
The documentation instructs users to configure API keys, establish external connections, and perform operational steps unrelated to idea refinement. This broadens the trust boundary and may trick agents or users into supplying credentials or enabling networked behavior under a misleading skill identity.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The markdown describes command execution, file operations, API-key setup, and external API use without prominent upfront warnings about system modification, credential handling, and data disclosure. In an agent setting, this can lead to users unknowingly authorizing sensitive actions or exposing secrets because the risk is buried in operational text rather than clearly disclosed.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.