Back to skill

Security audit

Java Dev Manual Tool Free

Security checks across malware telemetry and agentic risk

Overview

This looks like a Java coding-standards reference, but it requests command execution and includes broad, under-scoped action instructions beyond a simple handbook.

Install only if you are comfortable with a Java reference skill that can request command execution. Treat it as guidance content, not an automation tool, and avoid letting it run network checks, deployment steps, or file-changing operations unless you explicitly asked for them and reviewed the command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Description-Behavior Mismatch

Medium
Confidence
91% confidence
Finding
The skill is presented as a read-only Java conventions handbook, but its body advertises operational behaviors such as create/query/modify/delete, import/export, save, and conversion. This mismatch can cause an agent to grant the skill broader authority than intended or invoke exec-backed actions under the false assumption that they are part of the documented capability, increasing the risk of unintended command execution or unsafe automation.

Intent-Code Divergence

Medium
Confidence
80% confidence
Finding
The documentation claims the skill is pure Markdown-driven and needs no external connectivity, yet elsewhere instructs users to test network connectivity via ping/proxy/firewall checks and says performance depends on network environment. In a skill with exec permission, this inconsistency can mislead an agent or user into performing unnecessary system/network diagnostics, expanding behavior beyond a harmless reference manual.

Vague Triggers

Medium
Confidence
88% confidence
Finding
The trigger conditions say the skill should be used for broad tasks like code generation, programming assistance, debugging, testing, and deployment, which substantially exceed the stated purpose of a Java conventions quick-reference manual. Overbroad invocation criteria can cause the skill to activate in contexts where users expect implementation or operational help, increasing the chance that an exec-capable agent performs actions based on non-authoritative handbook content.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.