Back to skill

Security audit

interview-me

Security checks across malware telemetry and agentic risk

Overview

This skill does not show malware behavior, but its stated interview purpose conflicts with broad automation, file/API, credential, and command-execution guidance.

Review carefully before installing. There is no evidence of destructive code or exfiltration, but the skill asks for broad agent tools and describes much more than intent interviewing. Only use it in an environment where command execution and file access are acceptable, and require explicit user confirmation before any file, API, credential, or shell-command activity.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

High
Confidence
97% confidence
Finding
The manifest presents this as a narrow intent-extraction interview skill, but the body describes broad automation, data handling, and execution-oriented behavior. This capability mismatch is dangerous because reviewers or agents may grant the skill more trust and invoke it in contexts where hidden or unjustified operational behavior becomes possible.

Context-Inappropriate Capability

High
Confidence
99% confidence
Finding
Declaring exec for a skill whose stated purpose is asking clarifying questions violates least privilege. If invoked by an agent, this unnecessary execution surface could enable command execution, environment access, or abuse through prompt/parameter manipulation despite the skill not needing such power for its advertised function.

Context-Inappropriate Capability

High
Confidence
96% confidence
Finding
The documentation introduces unrelated capabilities such as GitHub validation, exports, file handling, credential setup, and command troubleshooting that materially expand the implied attack surface. In the context of an interview skill, these claims can normalize unnecessary access to external data, files, or secrets and mask risky behavior behind an innocent label.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The core-function description contradicts the manifest by describing generic parameter parsing and processing rather than iterative one-question-at-a-time interviewing. This inconsistency increases the chance of unsafe invocation and weakens security review because operators cannot reliably determine what the skill is supposed to do.

Vague Triggers

High
Confidence
93% confidence
Finding
A vague trigger condition like 'when the user needs related operations' can cause the skill to activate in situations far outside its legitimate purpose. Because this skill also claims broad operational capabilities, accidental or overly broad invocation could expose users to unintended file, command, or API-related actions.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.