Back to skill

Security audit

Iris Formatter Tool Free

Security checks across malware telemetry and agentic risk

Overview

This IRIS formatter is mostly a code-review guide, but it includes command execution and possible IRIS server credentials without clear limits.

Install only if you specifically need IRIS/ObjectScript formatting or review. Avoid providing IRIS server credentials or allowing command execution unless you have asked for compile validation and understand what system the agent will access.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
92% confidence
Finding
The skill is presented as a formatter and basic standards checker, but the documented capabilities expand into create/modify/delete, save, export, and conversion workflows. This broadens the operational scope from passive analysis into potentially state-changing actions, which can lead an agent to alter user code or files without clear consent boundaries or safety constraints.

Context-Inappropriate Capability

Medium
Confidence
89% confidence
Finding
For a code-formatting and standards-checking skill, introducing IRIS server connectivity and credential configuration expands the trust boundary unnecessarily into authenticated external systems. An agent following this guidance could prompt for, handle, or use credentials and interact with live infrastructure despite the skill's nominally local, low-risk purpose.

Intent-Code Divergence

Medium
Confidence
87% confidence
Finding
The document claims the tool is pure Markdown instruction-driven and needs no extra API key, yet nearby text also requires server credentials and describes MD+EXEC operation. This inconsistency obscures the real execution and access model, making it easier for users or agents to underestimate the risk of command execution or authenticated system interaction.

Vague Triggers

High
Confidence
95% confidence
Finding
The trigger conditions are excessively broad, covering generic development, debugging, testing, and deployment scenarios rather than narrowly targeting IRIS formatting and standards review. This can cause the skill to activate in many unrelated contexts, increasing the chance that an agent follows its instructions or uses its tools when a safer, more specific skill or no skill should apply.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill documents modify/save/export behaviors without warning that these actions may change user code or files. In an agent setting, omission of change-management safeguards can lead to silent or unexpected modifications, data loss, or overwriting user work, especially when paired with exec capability.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.