Back to skill

Security audit

JavaScript开发工具

Security checks across malware telemetry and agentic risk

Overview

This JavaScript helper is not clearly malicious, but it asks for command and file-writing power while documenting broad, inconsistently scoped automation features.

Review before installing. Use this only if you are comfortable granting a JavaScript assistant read, write, and command execution authority, and keep commands and file changes explicitly user-directed. The artifact does not show exfiltration or hidden persistence, but its permissions and automation claims are broader than its JavaScript-focused description.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (5)

Description-Behavior Mismatch

Medium
Confidence
93% confidence
Finding
The skill is presented as a JavaScript coding/review assistant, but the documentation expands its scope to file processing, API integration, search, and command execution. This capability creep weakens least-privilege expectations and can mislead users or agents into granting broader actions than are necessary for the stated purpose.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Advertising system command execution for a JavaScript writing/review skill is dangerous because exec enables arbitrary OS-level actions unrelated to code review. If an agent follows the skill literally, this can lead to unauthorized command execution, filesystem changes, or chaining into broader compromise.

Context-Inappropriate Capability

Low
Confidence
82% confidence
Finding
The skill claims API integration and information retrieval capabilities that are not clearly necessary for its JavaScript-focused purpose. While less severe than exec, unnecessary network and retrieval capabilities expand the attack surface and can enable unintended data access or exfiltration in agent workflows.

Intent-Code Divergence

Medium
Confidence
90% confidence
Finding
The document inconsistently describes the skill as both pure Markdown/natural-language driven and execute-capable. This discrepancy can cause users or orchestrators to underestimate the skill's privilege level, increasing the likelihood that dangerous execution features are enabled without appropriate scrutiny.

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The skill advertises file writing, external API calls, and command execution without strong user-facing warnings about side effects or security impact. In an agent setting, missing warnings reduce informed consent and make it easier for high-impact actions to be triggered under the guise of routine JavaScript help.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.