Back to skill

Security audit

Key Vault Manager Free

Security checks across malware telemetry and agentic risk

Overview

This skill is a key-management helper with expected secret-handling features, but its instructions are too broad and under-scoped for safe installation without review.

Review this before installing. Use it only for explicit key-management tasks, inspect the actual MCP repository before registering it, restrict allowed API destinations, and require confirmation plus a diff or backup before any file write that restores real secrets.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (4)

Context-Inappropriate Capability

Low
Confidence
74% confidence
Finding
The documentation instructs automatic shell-based network diagnostics and retries using `ping`, even though the skill's purpose is key handling. In a skill with `exec` capability, introducing unrelated command execution pathways increases attack surface and can normalize host command execution for troubleshooting, which may be repurposed for reconnaissance or unsafe automation.

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger condition says to use the skill for project management, task planning, progress tracking, and team collaboration, which is unrelated to a key-vault tool. Overbroad or mismatched triggers can cause the agent to invoke a secret-capable skill in inappropriate contexts, unnecessarily expanding exposure to file, exec, and secret-adjacent operations.

Missing User Warnings

Medium
Confidence
91% confidence
Finding
The skill describes writing real secrets back to disk through placeholder substitution, but does not present a prominent warning about modifying local files or the risks of overwriting sensitive material. In a secret-management context, silent or poorly signposted write-back behavior can lead to accidental persistence of secrets, corruption of scripts, or unintended modification of files selected by the agent.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill promotes local HTTP proxying with secret injection but does not clearly warn that request bodies, prompts, headers other than the secret, and response data may still be transmitted to third-party services. In the context of a key-vault tool, users may wrongly infer that the entire interaction is 'safe,' when only the key is protected, which can lead to disclosure of sensitive business data to external APIs.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.