Back to skill

Security audit

深度研究工具

Security checks across malware telemetry and agentic risk

Overview

This research skill is not malicious, but it asks for broad command and file authority without clearly limiting how those powers should be used.

Install only if you are comfortable letting the agent run shell commands for research tasks. Before use, restrict commands to specific search, parsing, and report-generation actions; review any pip install, script execution, file write, or external API call before it runs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Description-Behavior Mismatch

Medium
Confidence
76% confidence
Finding
The documented 'core functionality' expands the skill into generic file handling, API integration, and command execution beyond its stated research purpose, while the manifest allows the powerful 'exec' tool. That broadened scope can encourage an agent to perform unnecessary privileged actions, increasing the attack surface for command misuse, unsafe file access, or unintended external calls if user input is later incorporated into those actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.